Cloud SecurityAdvancedAttack Technique3 validated evidence records

Living off the Cloud (LOTC)

Also known as: Cloud-native abuse, Abuse of legitimate cloud services

30 sec

Abuse of legitimate cloud identities, APIs, services, storage, automation, and administrative capabilities to conduct malicious activity while blending into normal cloud operations.

Know

What is Living off the Cloud?

Living off the cloud extends the living-off-the-land idea to hosted environments. Instead of importing obvious malicious tooling, attackers use the organization’s existing cloud services, APIs, credentials, storage, serverless functions, Kubernetes, SaaS integrations, and administrative features to move, persist, and exfiltrate data.

Why it matters

Google Cloud’s 2026 Cloud Threat Horizons reporting describes attackers pivoting from compromised endpoints into Kubernetes and cloud infrastructure and using legitimate cloud services for data theft. Cloud-conscious eCrime activity also surged in CrowdStrike’s 2026 threat hunting data.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationResearch / emerging practice

Google documents agent-enabled credential harvesting and AI resource theft

2026-09-08Google Threat Intelligence Group / Mandiant

Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.

Why this is evidence

The timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.

See the source — Google Threat Intelligence Group / Mandiant: GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Technical ValidationMeasured outcome

Cloud and SaaS incidents were dominated by identity compromise and data theft

2026-H1Google Cloud / MandiantCloud and SaaS

Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.

Why this is evidence

The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.

See the source — Google Cloud: Cloud Threat Horizons Report H1 2026
Technical ValidationMeasured outcome

CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours

2026-08-03CrowdStrike Counter Adversary OperationsCross-sector

CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.

Why this is evidence

These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.

See the source — CrowdStrike: 2026 Threat Hunting Report

Understand the mechanics

How it works

  1. 1

    Compromise a cloud-capable identity or endpoint.

  2. 2

    Discover accessible cloud services, APIs, roles, and secrets.

  3. 3

    Use native administration and automation rather than obvious malware.

  4. 4

    Move data through approved cloud storage or services.

  5. 5

    Maintain access using legitimate identities, tokens, workloads, or integrations.

Practice

What to watch for

  • Unusual API calls by valid identities
  • New cloud resources or serverless functions
  • Bulk data movement to legitimate storage
  • Cross-service role assumption
  • Kubernetes or cloud admin activity from a user who does not normally perform it

Perform

What to do

  1. 1

    Revoke compromised identities and workload credentials.

  2. 2

    Preserve cloud control-plane and data-access logs.

  3. 3

    Identify attacker-created resources and persistence.

  4. 4

    Review IAM paths and connected workloads.

  5. 5

    Contain data egress while preserving evidence.

How to reduce the risk

  • Cloud-native logging
  • Least privilege
  • Workload identity
  • Egress monitoring
  • CSPM/CNAPP
  • Short-lived credentials
  • Behavior analytics
  • Separate admin roles

Business impact

  • Silent cloud persistence
  • Data theft
  • Cryptocurrency theft
  • Resource abuse
  • Difficult attribution because legitimate tools are used

What different roles should do

Cloud Engineering

  • Treat control-plane activity as security telemetry

Security

  • Detect abnormal sequences of legitimate cloud actions, not only malware signatures

Framework & standards context

  • MITRE ATT&CK Cloud techniques
  • NIST CSF 2.0 Detect

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02