
Top Cloud Malware Attacks Businesses Should Know About
Cloud malware is no longer a theoretical threat that persists in the cloud; it is using traditional security controls and lives in the same approved services.crossed by your teams every day. The techniques that malware is using to deliver exploits through cloud environments are changing quickly and are becoming increasingly untraceable.
Knowing how to protect your data from malware is not just good information; it is essential information that can be the difference between securing your operation and a catastrophic breach of sensitive data.
One of the most prevalent attackis to upload dangerous files to reputable and known cloud storage services; including Google Drive, Dropbox, or Microsoft OneDrive; none of which receive the same level of security scrutiny as email. Cloud storage services do not require the traditional context of personal trust; they are inherently trusted by the users of the service.
The danger is when those infected files are shared internally, amongst users, or externally with clients and partners. One document shared Ida file that has malware and is shared through your trusted cloud RFID cloud storage service can rapidly spread through the entirety of your organization, especially if your users are downloading and executing files without any validation.
Most typical Halbumn security toolset region bind Found are usually overly stretched and unable to detect threats commingling in these environments because these platforms are perceived as trusted environments. Too many security solutions do not put the same effort into scanning files in the cloud that they put into scanning files that are email attachments or downloads from dubious sites.
What you need to do is implement a comprehensive scanning solution that is designed specifically for cloud storage platforms that can detect suspicious content during the upload process and avoid spreading malicious files around your organization.
Phishing campaigns aimed straight at cloud service credentials have evolved to be extremely sophisticated. Attackers create incredibly convincing fake log-in webpages, that mimic popular services like Office 365, Google Workspace, or Salesforce, leading employees to enter their username and password into the attacker controlled webpages.
Once the attacker gets the stolen credentials, they can access your cloud accounts with no security alerts that would typically trigger for traditional security. The attacker can then use the information for many pernicious purposes – install malware, steal sensitive documentation, access communications between users, or even act as an authenticated user to launch attacks on other systems.
These attacks provide great appeal to cybercriminals because the activity looks to external observers as if it is legitimate activity by a legitimate user. Standard security monitoring is unlikely to flag fallback activity suspicious because it is likely coming from an authenticated user with permission to access the data.
So, yes, in addition to cyberattack exploitation of business communications and sensitive information of a business, when an attacker can get to the credentials and gain access to cloud-based systems they are likely in and permitted because they are (alternatively) logged into your cloud accounts!
Multi-factor authentication is your best defense against credential based attacks. Even if they get your password, they will still need access to the second authentication process for log-in to their victim's system!
Fileless malware is one of the more aggregated and sophisticated threats to cloud environments. As opposed to conventional executable files, these attacks run fully in system memory utilizing legitimate system tools and processes to execute malicious actions.
In cloud environments, fileless attacks often exploit PowerShell scripts, Windows Management Instrumentation, or other administrative tools that are built-in to the system to run malicious code. Consequently, these scripts can remain undetected for long periods without leaving the conventional file signatures that antivirus usually looks for.
Traditional antivirus solutions struggle significantly with fileless threats because there are no malicious files to scan. Furthermore, because the attacks run using legitimate system processes and tools, active detection will be extremely challenging with signature security-based forms of protection.
Defense against fileless threats will require functionality for behavioral monitoring combined with threat intelligence that allows for risk patterns and behavioral anomalies, rather than just using file-based detection. Functionalities like behavioral monitoring can analyze system behavior to see when legitimate tools are being used maliciously.
Software-as-a-Service integrations have created another attack vector that many organizations do not consider. Attackers create an application that looks legitimate and asks for OAuth permissions or other forms of integration access to popular platforms such as Slack, Microsoft Teams, or Google Workspace.
Once a user accepts the integration, the attacker can gain access using the application's permissions without direct credential theft. The attacker could read emails, access files, read communications, or simply abuse the integration to get malicious software into the organization's environment.
These attacks are particularly effective because malicious applications are often presented professionally, requesting reasonable permissions that look acceptable. For example, a user may not realize that by allowing an integration, they are granting access to an attacker, which then enables the attacker to operate in their cloud environment using real application credentials.
Regularly reviewing authorized SaaS integrations should be included in the organization's standard security measures. Additionally, organizations should audit what applications have permission to access their systems, those permissions, and if the integrations are still needed and trusted.
Cloud malware has progressed from being a niche concern to being a serious threat that affects small and large businesses. From fileless attacks that hide in plain sight to compromised SaaS integrations that are abusing legitimate permissions, cybercriminals are finding cunning means of infiltrating cloud environments.
The solution to protection is remaining alert, educating your team on emerging threats, and implementing advanced security tools that are specifically built for cloud platforms. Understanding the threats and putting measures in place to limit exposure will help businesses proactively protect their resources and maintain their operational continuity.
TIME BUSINESS NEWS

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Android Authority
35 minutes ago
- Android Authority
Dedicated Google Maps Local Guides have a chance at a free Google Fi plan
Edgar Cervantes / Android Authority TL;DR Select contributors to Google Maps' Local Guides program have received a free three-month Google Fi Unlimited plan (worth up to $195). As has been the case for a few years now, the offer is limited to first-time Google Fi users who port their existing number, vastly restricting eligibility. There's no clear pattern for who gets the perk, though recipients typically have at least level four status in the program. Google Maps has a long-running Local Guides program that rewards volunteers who contribute photos, reviews, updates, and answers about places to Google Maps. The program was fairly coveted back in the day, with perks that often made people jealous (free Google Drive storage, discounts on Pixels, and even a free Nest Mini!). The rewards aren't as exciting and frequent anymore, but there's still a chance to come across a great perk. Case in point, this Reddit user got a free Google Fi plan for the rest of the year. As per the email, the user can enjoy any Unlimited plan at no cost for three months, up to a value of $195. The email's wording is a bit off, as we're still in July, so three months do not cover the rest of the year. This discrepancy can be explained by the fact that this isn't a new perk, as it has been around for a few years now. Users are usually offered this around October, and it seems Google didn't update the language on the email this time around. Alternatively, there's always the possibility that the user is lying, and this is an old email, in which case, we've been bamboozled. The fine print isn't visible in this email, but we know from previous rollouts that the offer is limited to first-time Fi customers who decide to port their number in from their existing carrier. This caveat substantially dulls the deal, but if you were planning to give Google Fi a shot, getting a perk worth $195 is a pretty sweet way to start it off. It's still unclear what criteria Google uses to give out this perk. You do need to have some level of Local Guides contribution, at least above level four, as that is when you get the first perk: a custom badge on your Google Maps profile. But beyond that, it's in the air. Users at levels as high as seven haven't received this perk yet, and it's not yet known what the user's level was who received this perk this week. If you've ever received this free Google Fi perk for being an active Google Maps Local Guide, let us know your level in the comments below! Follow


Forbes
an hour ago
- Forbes
The Latest Version Of MacPaw's CleanMyMac Can Now Clean Up Cloud Storage Accounts
Say goodbye to manually cleaning up cloud storage with the latest update to MacPaw's CleanMyMac. The ... More Plus tier of the popular Mac utility software can now clean up cloud storage accounts including iCloud, Google Drive, and OneDrive. Ukrainian software developer MacPaw has been developing utilities for Mac and iOS users for some years now. Today sees the launch of a new feature for MacPaw's CleanMyMac utility that expands the software's capability beyond simply cleaning up local devices. Now CleanMyMac can take care of files stored in the cloud. Cloud Cleanup is a new feature available in CleanMyMac that gives users complete control and secure access over connected cloud accounts, including iCloud, Google Drive, and OneDrive. This new feature is the latest part of MacPaw's popular utility that has been helping Mac users track down and remove unnecessary files clogging up their hard drive or SSD. With CleanMyMac, space can be freed up, sync times improved and storage costs reduced. Users can also dive deeper into each cloud account using two views. The first is a scrollable list ... More that automatically surfaces old and unused files. The second is a visual map that clusters files and folders by size to make them easier to review and delete. 'Managing cloud storage can be confusing and costly, especially when unused files just sit there, piling up without users even realizing it. When storage limits are reached, it can slow down syncing and backups, impacting overall performance without users realizing the cause,' says Oleksandr Kosovan, CEO and founder of MacPaw. 'Our millions of users, who have long trusted CleanMyMac to keep their devices clean and running, have been asking for this kind of support. With Cloud Cleanup, we're giving them a smart, simple way to take control of their storage across many services, all in one place.' Intuitive Cloud Management Managing cloud storage can often involve jumping between different services and platforms, manually sorting files by size or date, before individually deleting unwanted files. Cloud Cleanup is built on the same principles as CleanMyMac. You can now unsync cloud storage accounts with Cloud Cleanup, the latest feature available with the ... More Plus tier of CleanMyMac. Working entirely on-device without saving or accessing any files stored in the cloud, users are shown a clean, tile-based dashboard with key insights for each connected cloud storage account. Information includes how much space is being used and the percentage of a user's files that are exclusively stored in the cloud. Users can also dive deeper into each cloud account using two views. The first is a scrollable list that automatically surfaces old and unused files. The second is a visual map that clusters files and folders by size to make them easier to review and delete. Cloud Cleanup provides two core tools for cleaning up cloud storage accounts. The first method is called Remove. This helps users free up space in their cloud accounts by identifying and then removing any unnecessary files. The new Cloud Cleanup feature in the latest version of CleanMyMac should make organising cloud ... More storage much easier. Unsync is a feature that desynchronizes and removes local copies of files stored in the cloud, letting users reclaim storage on their Mac. Smart alerts notify the user when action is needed, such as when unused files are detected or the user is reaching the limit of their storage space. Seamless Integration And Compatibility Cloud Cleanup works with leading cloud storage platforms like Google Drive and OneDrive through their desktop apps when users are signed into the connected accounts. It also works with iCloud when the user is signed into their Apple account. This multi-provider approach to managing cloud storage means CleanMyMac can now offer compatibility with popular cloud services. MacPaw also says it plans to add even more cloud storage services and platforms in the future. CleanMyMac will be available in Basic and Plus plans from July 29, 2025. Cloud Cleanup will only be available as part of the Plus tier. The Plus Plan is $65.40/year or $195.95 one-time. The Basic Plan is $40.20/year or $119.95 one-time.


CNET
5 hours ago
- CNET
Get Lifetime Access to Microsoft Office 2024 With This StackSocial Deal
Microsoft's software is hard to avoid, especially if you're looking to get stuff done. That's mostly because it works well, and it's the de facto option for a ton of people and businesses. The Microsoft Office 365 subscription is a popular way to get access to the company's Office suite of apps, but who wants to pay $10 a month in perpetuity to get Office software? Thankfully, Office 365 is also available as a one-time purchase, and it's even on sale right now. StackSocial is offering a $20 discount on the direct price you'd find at Microsoft, bringing the price down to $130 -- but it's selling fast. This deal grants you lifetime access to the 2024 desktop versions of Word, Excel, PowerPoint and OneNote. The package is designed for individuals and allows you to use the apps on one PC or Mac. StackSocial notes that this license will be connected with your Microsoft Account and not your actual device, but this is a one-time use code. That means that the code will bind to your Microsoft email account and if you log in from one device, you'll be automatically logged out of any other device you might be signed into. You can only make this shift once every 90 days except in cases of hardware failure, so be sure you redeem and download on a device you plan to use often. You can learn more about this on Microsoft's FAQ page. Be aware that you must redeem your code within seven days of purchase. Hey, did you know? CNET Deals texts are free, easy and save you money. You won't get all of the benefits of signing up for the Microsoft 365 subscription, such as OneDrive cloud storage or Microsoft Copilot. A 365 subscription will also cost you $10 a month or $100 for the year, and those fees can add up over time. If you don't necessarily need the latest updates, there are some cheaper options available. We've found deals on both Office 2019 and Office 2021, starting at just $30 right now. There is a free Microsoft Office online alternative that you can use, but it lacks several features and can only be used in the browser. Looking to invest in a new device at a discount? We've got you covered with plenty of laptop and gaming PC deals. Why this deal matters The standard Office Home from Microsoft will run you $150, so the StackSocial deal can help you save $20 off that price. If you were to opt for a yearly Microsoft 365 plan instead, you're looking at $100 annually. If you see yourself using Microsoft for over a year, and don't need al the added extras that Microsoft 365 offers, this is a great deal to take advantage of.