08/01/2020
Drake Lyrics Used as Calling Card in Malware Attack
Link
Pastebin
Delivery and Exploitation
10/01/2020
Phishing on Sway
Link
Sway
Delivery and Exploitation
16/01/2020
JhoneRATCloud based Python RAT
Link
Google Drive, Google Forms,Twitter
Delivery and Exploitation/Command And Control
27/01/2020
Aggah delivering malware from pastebin
Link
Pastebin, Blogspot
Delivery and Exploitation
30/01/2020
Iran-linked hackers pose as journalists in email scam
Link
Google Sites
Delivery and Exploitation
30/01/2020
Check Point details two flaws in Azure that could have allowed takeover
Link
Azure
Actions on Objective
31/01/2020
Winnti Group Infected Hong Kong Universities With Malware
Link
GitHub, Google Docs, Pastebin
Command and Control
05/02/2020
Bitbucket Abused to Infect 500,000+ Hosts with Malware Cocktail
Link
BitBucket
Delivery and Exploitation
05/02/2020
Espionage campaign targeting Malaysia government officials
Link
Google Drive
Delivery and Exploitation
13/02/2020
Gaza group strikes targets in Palestinian territories
Link
Dropbox, Egnyte
Delivery and Exploitation
17/02/2020
“The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign
Link
GitHub
Delivery and Exploitation
18/02/2020
Dharma Ransomware Attacks Italy in New Spam Campaign
Link
OneDrive
Delivery and Exploitation
19/02/2020
Details of 10.6 million MGM hotel guests posted on a hacking forum
Link
N/A
Actions on Objective
19/02/2020
Chinese hackers have breached online betting and gambling sites
Link
Dropbox
Delivery and Exploitation/Command And Control
20/02/2020
Cybergang Favors G Suite and Physical Checks For BEC Attacks
Link
Google Gmail
Delivery and Exploitation
21/02/2020
Phishers Are Using Google Forms to Bypass Popular Email Gateways
Link
Google Forms
Delivery and Exploitation
25/02/2020
’Cloud Snooper’ Attack Bypasses Firewall Security Measures
Link
AWS
Actions on Objective
03/03/2020
Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations
Link
Google Drive
Delivery and Exploitation
03/03/2020
Microsoft OneNote Used To Sidestep Phishing Detection
Link
OneNote
Delivery and Exploitation
06/03/2020
FBI Warns of BEC Attacks Abusing Microsoft Office 365, Google G Suite
Link
Google Gmail, Outlook.com
Delivery and Exploitation
07/03/2020
Data-Stealing FormBook Malware Preys on Coronavirus Fears
Link
Google Drive
Delivery and Exploitation
10/03/2020
Phishing Attack Skirts Detection With YouTube
Link
YouTube
Delivery and Exploitation
14/03/2020
BlackWater Malware Abuses Cloudflare Workers for C2 Communication
Link
Cloudflare
Command and Control
18/03/2020
Politically Themed Cyber Activity Highlights Regional Opposition to Middle East Peace Plan
Link
Google Drive
Delivery and Exploitation
19/03/2020
The Curious Case of the Criminal Curriculum Vitae
Link
Google Drive
Delivery and Exploitation
20/03/2020
Exchange rate service’s customer details hacked via AWS
Link
AWS
Actions on Objective
24/03/2020
How Attackers Could Use Azure Apps to Sneak into Microsoft 365
Link
Azure
Actions on Objective
25/03/2020
New Router DNS Hijacking Attacks Abuse Bitbucket to Host Infostealer
Link
BitBucket
Delivery and Exploitation
20/03/2020
India’s Vijay Sales Leaks Private Information through Exposed Amazon Backup Server
Link
AWS
Actions on Objective
20/03/2020
India’s Vijay Sales Leaks Private Information through Exposed Amazon Backup Server
Link
AWS
Actions on Objective
31/03/2020
Holy water: ongoing targeted water-holing attack in Asia
Link
GitHub, Google Drive
Delivery and Exploitation/Command And Control
31/03/2020
New Raccoon Stealer uses Google Cloud Services to evade detection
Link
Google Drive
Command and Control
01/04/2020
Wave of SBA attacks using COVID-19 as a lure to distribute malware
Link
Google Drive
Delivery and Exploitation
13/04/2020
Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain
Link
GitHub, Google Sites
Delivery and Exploitation
20/04/2020
Threat Actors Masquerade as HR Departments to Steal Credentials
Link
Sway, OneDrive
Delivery and Exploitation
22/04/2020
Customer complaint phishing pushes network hacking malware
Link
Google Drive
Delivery and Exploitation
24/04/2020
BazarBackdoor: TrickBot gang’s new stealthy network-hacking malware
Link
Google Docs
Delivery and Exploitation
28/04/2020
Grandoreiro: How engorged can an EXE get?
Link
GitHub, Dropbox, Pastebin, 4shared
Delivery and Exploitation
30/04/2020
Spear-phishing campaign compromises executives at 150+ companies
Link
Sway, OneNote, Sharepoint
Delivery and Exploitation
05/05/2020
Game patch gives hackers access to development content on Amazon S3
Link
AWS
Actions on Objective
06/05/2020
Two new criminal campaigns targeting the global financial industry with the EVILNUM malware
Link
Google Drive, GitLab
Delivery and Exploitation/Command And Control
07/05/2020
Brazilian trojan banker targets Portuguese users using browser overlay
Link
Google Drive, Google Sites
Delivery and Exploitation/Command And Control
11/05/2020
Astaroth malware hides command servers in YouTube channel descriptions
Link
Youtube
Command and Control
18/05/2020
MFA Bypass Phish Caught: OAuth2 Grants Access to User Data Without a Password
Link
Office 365 Application Suite
Actions on Objective
21/05/2020
Phishing in a Bucket: Utilizing Google Firebase Storage
Link
Google Firebase
Delivery and Exploitation
26/05/2020
Malware from Turla using Gmail as the command and control
Link
Google Gmail
Command and Control
01/06/2020
Enterprise-grade’ BazarBackdoor malware delivered via spear phishing emails
Link
Google Docs
Delivery and Exploitation
08/06/2020
US energy providers hit with new malware in targeted attacks
Link
Dropbox
Delivery and Exploitation
09/06/2020
More S3 Buckets Compromised with Magecart and Malicious Redirector
Link
AWS
Actions on Objective
10/06/2020
Office 365 phishing baits business owners with relief payments
Link
Dropbox
Delivery and Exploitation
11/06/2020
Machine-learning clusters in Azure hijacked to mine cryptocurrency
Link
Azure
Actions on Objective
18/06/2020
Wells Fargo phishing baits customers with calendar invites
Link
Google Calendar
Delivery and Exploitation
22/06/2020
IndigoDrop spreads via military-themed lures to deliver Cobalt Strike
Link
Pastebin
Delivery and Exploitation
06/07/2020
New release of Lampion trojan spreads in Portugal
Link
Google Cloud Storage
Delivery and Exploitation
07/07/2020
Microsoft Office 365 users targeted in SurveyMonkey phishing
Link
SurveyMonkey, Sharepoint
Delivery and Exploitation
08/07/2020
Microsoft warns of Office 365 phishing via malicious OAuth apps
Link
Office 365 Application Suite
Actions on Objective
14/07/2020
Brazil’s Banking Trojans Go Global
Link
YouTube, Facebook, Google Docs, Google Sites
Delivery and Exploitation/Command And Control
14/07/2020
New RATicate campaign using GuLoader
Link
Google Drive, Dropbox, OneDrive
Delivery and Exploitation
16/07/2020
Invoice Themed Phishing Emails Are Spreading from Trusted Links
Link
Dropbox
Delivery and Exploitation
18/07/2020
New phishing campaign abuses a trio of enterprise cloud services
Link
Azure,Dynamics, IBM Cloud
Delivery and Exploitation
21/07/2020
Phishing campaign uses Google Cloud Services to steal Office 365 logins
Link
Google Cloud Storage, Google Drive
Delivery and Exploitation
21/07/2020
Fake email from Italian University delivering LokiBot
Link
Pastebin
Delivery and Exploitation
27/07/2020
Office 365 phishing baits employees with fake SharePoint alerts
Link
Google Firebase
Delivery and Exploitation
28/07/2020
Sneaky Doki Linux malware infiltrates Docker cloud instances
Link
AWS, Azure
Actions on Objective
10/08/2020
A hacker releases the databases of gun exchange, hunting, and kratom sites
Link
AWS
Actions on Objective
10/08/2020
A hacker releases the databases of gun exchange, hunting, and kratom sites
Link
AWS
Actions on Objective
12/08/2020
A Big Catch: Cloud Phishing from Google App Engine and Azure App Service
Link
Google App Engine, Azure
Delivery and Exploitation
17/08/2020
First Crypto-Mining Worm to Steal AWS Credentials
Link
AWS
Actions on Objective
21/08/2020
Outlook “mail issues” phishing from Azure
Link
Azure
Delivery and Exploitation
24/08/2020
DeathStalker targets the financial sector
Link
GitHub, Google Plus, Imgur, Reddit, Tumblr, Twitter, YouTube, Wordpress
Command and Control
24/08/2020
Malicious Actors Target AWS Accounts
Link
AWS
Delivery and Exploitation
25/08/2020
Attackers are hosting phishing landing pages on Box to bypass security controls
Link
Box
Delivery and Exploitation
25/08/2020
Phishing attacks exploiting AWS
Link
AWS
Delivery and Exploitation
26/08/2020
Blogspot Serves as a COVID-19 Scamming Hotspot
Link
Blogspot
Delivery and Exploitation
31/08/2020
Phishing with Slack-Files.com
Link
Slack
Delivery and Exploitation
02/09/2020
Phishing scam uses Sharepoint and One Note to go after passwords
Link
Sharepoint, OneNote
Delivery and Exploitation
03/09/2020
New Email-Based Malware Campaigns Target Businesses
Link
Google Sites
Delivery and Exploitation
25/09/2020
Microsoft Kills 18 Azure Accounts Tied to Nation-State Attacks
Link
Azure, OneDrive, GitHub
Command and Control
29/09/2020
OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks
Link
Office 365 Application Suite
Actions on Objective
29/09/2020
Spear Phishing Campaign Delivers Buer and Bazaar Malware
Link
Google Docs
Delivery and Exploitation
30/09/2020
Four npm packages found uploading user details on a GitHub page
Link
GitHub
Command and Control
05/10/2020
Cryptojacker Targets Exposed Docker Daemon APIs
Link
AWS
Actions on Objective
05/10/2020
Malware campaigns deliver payloads via obscure paste service
Link
Paste.nre.com
Delivery and Exploitation
07/10/2020
Phishing emails lure victims with inside info on Trump's health
Link
Google Docs
Delivery and Exploitation
07/10/2020
Phishing attack spoofs IRS COVID-19 relief to steal personal data
Link
Sharepoint
Delivery and Exploitation
12/10/2020
BazarLoader used to deploy Ryuk ransomware on high-value targets
Link
Google Docs
Delivery and Exploitation
16/10/2020
APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services
Link
Github, Dropbox
Delivery and Exploitation/Command And Control
17/10/2020
Hackers now abuse BaseCamp for free malware hosting
Link
Basecamp
Delivery and Exploitation
19/10/2020
Coinbase phishing hijacks Microsoft 365 accounts via OAuth app
Link
Office 365 Application Suite
Actions on Objective
21/10/2020
LockBit uses automated attack tools to identify tasty targets
Link
Google Docs
Delivery and Exploitation
22/10/2020
Microsoft Teams Impersonation
Link
Google App Engine
Delivery and Exploitation
28/10/2020
Russian Turla hackers breach European government organization
Link
Pastebin
Command and Control
29/10/2020
Firestarter Android Malware Abuses Google Firebase Cloud Messaging
Link
Google Firebase
Command and Control
30/10/2020
Beware of Google Docs Spam
Link
Google Docs
Delivery and Exploitation
03/11/2020
Google Forms Abused to Phish AT&T Credentials
Link
Google Forms
Delivery and Exploitation
05/11/2020
Reverse shell botnet Gitpaste-12 spreads via GitHub and Pastebin
Link
Github, Pastebin
Delivery and Exploitation
09/11/2020
Phishing Campaign Tied to Trickbot Gang
Link
Google Docs
Delivery and Exploitation
13/11/2020
TroubleGrabber: Stealing Credentials Through Discord
Link
GitHub
Delivery and Exploitation
17/11/2020
LightBot: TrickBot’s new reconnaissance malware for high-value targets
Link
Google Docs, Google Drive
Delivery and Exploitation
20/11/2020
Phishing lures employees with fake 'back to work' internal memos
Link
Sharepoint
Delivery and Exploitation
26/11/2020
Digitally Signed Bandook Trojan Reemerges in Global Spy Campaign
Link
AWS, BitBucket, Dropbox
Delivery and Exploitation
26/11/2020
Massive Zoom phishing targets Thanksgiving meetings
Link
Google App Engine
Delivery and Exploitation
27/11/2020
Office 365 phishing abuses Oracle and Amazon cloud services
Link
AWS, Oracle
Delivery and Exploitation
02/12/2020
New backdoor used by Turla to exfiltrate stolen documents to Dropbox
Link
Dropbox
Command and Control
09/12/2020
New Malware Arsenal Abusing Cloud Platforms in Middle East Espionage Campaign
Link
Dropbox, Google Drive, Facebook, Github
Delivery and Exploitation/Command And Control
09/12/2020
njRAT using Pastebin as command server
Link
Pastebin
Command and Control
14/12/2020
Gitpaste-12 Worm Widens Set of Exploits in New Attacks
Link
GitHub, Pastebin
Delivery and Exploitation/Command And Control
16/12/2020
NSA warns of hackers forging cloud authentication information
Link
Azure
Actions on Objective
28/12/2020
GitHub-hosted malware calculates Cobalt Strike payload from Imgur pic
Link
GitHub, Imgur
Delivery and Exploitation