Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Cloud Security - From VPS to Phishing: Darktrace Exposes SaaS Hijacks through Virtual Infrastructure Abuse
Cloud Security Attacks Latest News News & Analysis Security Study & Research

From VPS to Phishing: Darktrace Exposes SaaS Hijacks through Virtual Infrastructure Abuse

Kirsten DoyleBy Kirsten DoyleAugust 22, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
VPS SaaS Hijacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Darktrace has uncovered a coordinated campaign of SaaS account takeovers. Attackers hid behind Virtual Private Servers, slipping into accounts, moving unseen, and wiping away the traces of phishing.

The pattern was consistent: suspicious logins from VPS-linked infrastructure, swift creation of inbox rules, and deleted emails, particularly those tied to phishing. What researchers found was a portrait of a campaign built on stealth, persistence, and the calculated use of virtual infrastructure.

What is a VPS, and Why Does it Matter?

A VPS provides dedicated computing resources on a shared physical server. For businesses and developers, it is a useful, legitimate tool. For attackers, it offers something else: scale, speed, and cover. 

VPS abuse is not new. But its rise in SaaS-targeted campaigns is notable. It allows attackers to sidestep geolocation controls by imitating local traffic. It lets them evade IP reputation checks with newly minted addresses. And it helps them blend into the daily rhythm of legitimate business activity.

Providers like Hyonix and Host Universal make this easier still. Their services can be deployed within minutes, at low cost, and with minimal digital trace. To a threat actor, that combination is irresistible.

Darktrace’s Investigation

In May this year, Darktrace’s Threat Research team looked into a surge of anomalous behavior tied to Hyonix infrastructure. The spike started in March, with alerts showing brute-force attempts, unusual logins, and inbox rule manipulation.

Two customer environments stood out. In one, mirrored compromises appeared across multiple devices. Logins came from unfamiliar endpoints. Emails were deleted to mask evidence of phishing attempts. Tracing the trail led back to Hyonix IPs.

In the second, attackers moved with more coordination. Multiple accounts logged in from rare VPS sources. Inbox rules were created with vague or obfuscated names. Recovery settings were modified, a signal of privilege escalation.

The pattern pointed to a campaign leveraging shared infrastructure across targets. 

In both cases, Darktrace’s Autonomous Response was not active. That absence mattered. Without automated containment, the activity escalated. With it, connections from rare VPS endpoints would have been blocked early. 

The Case Details

On 19 May, Darktrace saw two internal devices connect through Hyonix and Host Universal IPs. The logins occurred almost simultaneously with legitimate user sessions from distant geographies. That “impossible travel” was an early sign of hijacking. Shortly after, phishing-related emails were deleted from a compromised account’s “Sent Items” folder.

Elsewhere, in another customer network, attackers used VPS infrastructure from Hyonix, Mevspace, and Hivelocity. They satisfied MFA checks through stolen token claims. Once inside, they established persistence through inbox rules designed to pass unnoticed. One such rule automatically deleted messages from a senior executive, likely to suppress evidence of misuse.

Building Persistence 

The threat actors’ behavior was deliberate. Rules were given minimal or generic names to avoid scrutiny. Multiple accounts showed almost identical mailbox manipulations. Others showed signs of account recovery tampering and password resets. 

One network saw outbound spam with finance-themed subject lines, while another showed DNS queries to domains using fluxing, a popular evasion tactic. 

In a further twist, a compromised device attempted to install Splashtop, a remote access tool normally used for IT support. In this context, it suggested the malefactor sought durable, hands-on control of the environment.

Weaponizing VPS Services

This campaign shows how bad actors are weaponizing VPS services to obfuscate their operations in SaaS environments. These services are cheap, disposable, and practically invisible against traditional security checks.

Darktrace’s AI picked up the anomalies early: unusual logins, inbox rule creation, suspicious deletions. Indicators that static, rule-based tools often miss. But early detection alone is insufficient. Containment (ideally automated) is vital when attackers move at machine speed. 

Blending With Normal Traffic

J Stephen Kowski, Field CTO at SlashNext says the playbook isn’t new—it’s the same old tricks as you would see on a desktop: changing inbox rules, stealing tokens, resetting passwords, and cleaning up tracks

“The only twist is that it’s happening on a rented cloud desktop, which makes the activity blend in with normal traffic a slightly differently. The real issue is the first break-in—usually stolen logins, hijacked sessions, weak MFA, or a malicious app link. That’s where tools that watch sessions in real time, catch phishing across channels, block shady app approvals, and roll back mailbox tampering shut it down before that cloud desktop turns into a launchpad.”

Renting Trust

Attackers now rent trust, adds Jason Soroko, Senior Fellow at Sectigo. “Five dollar VPS nodes buy entry to your allow list and they accomplish this by getting a clean ASN and fresh IP making traffic feel like a trusted source, not a criminal. In this case, the adversary is riding live sessions and no longer just harvesting passwords. The mailbox becomes the control plane. Vague rules act like a kind of stealth policy.”

Concurrency, sequence, and locality must line up, Soroko adds. “If they do not, you must have a way to freeze the session, not the user. Make inbox rules visible, named, and attested. Alert on rule churn the way you alert on privilege churn. Score infrastructure by volatility and provenance, not brand. Expect remote tools to appear where they never should and block by context. Autonomous containment is a governance choice that decides outcomes. In this campaign, the absence of it gave the intruders time, which is the adversary’s most important currency.”

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Cloud Security Controls Explained: A Definitive Guide

March 19, 20269 Mins Read

Red Canary Flags Rapid Rise in Cloud-Based Attacks

August 11, 20253 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}