Skip to main content
Emerging ThreatsMalware & Ransomware

Cyber-Attackers Target Cloud and SaaS Environments With Identity-Based Threats

Rows of computer equipment and cloud-connected devices in a brightly-lit server room or office space.

"Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools," the Darktrace researchers wrote in a report published on August 3.

Darktrace frames "trust" as the new attack surface

Darktrace’s H1 2026 analysis describes a clear evolution in attacker behavior that began in 2025: threat actors moved away from broadly deployed malware and direct vulnerability exploitation toward compromising identities. Where 2025 attacks primarily targeted account credentials, the first half of 2026 extended that focus to email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling and non‑human identities. The upshot, the company says, is that the implicit trust built into these systems — not just technical flaws — has become the principal vector for intrusion.

A single compromised SaaS account can cascade across layers

Darktrace highlights an incident in which a single compromised SaaS account produced malicious activity spanning email, SaaS and network layers. The account compromise led to inbox rule changes and the launch of phishing attacks. Individually, none of the observed indicators were decisive; collectively, they demonstrated a clear intrusion. That pattern underscores the report’s central claim: attackers are leveraging legitimate access to inherit trust and multiply impact across otherwise distinct systems.

Hijacked dependencies and blockchain services broaden reach — Axios, AMOS and Phexia cited

The report documents multiple cases where threat actors exploited trusted elements of the digital supply chain. In April, attackers hijacked the Axios JavaScript library to distribute remote access trojans (RATs). Darktrace notes Axios is downloaded over 100 million times a week and is used as a dependency in countless developer environments and CI/CD pipelines, amplifying the compromise.

Researchers also observed attackers abusing legitimate blockchain infrastructure to distribute infostealers, including AMOS and Phexia. Darktrace noted those services are frequently used by users with limited security resources and that they can enable malicious actors to reach a much wider victim base.

Email attacks: authentication passes, longer text, targeted social engineering

Email‑based attacks in H1 2026 trended toward higher quality and specificity rather than sheer volume. Around two‑thirds of phishing emails observed passed DMARC email validation protocols, a metric Darktrace uses to argue that authentication alone is no longer sufficient to protect accounts. Other measured shifts include an increase in long, text‑heavy phishes — 37% of phishing attacks contained a high volume of text in H1 2026, up from 32% in the same period in 2025 — and rising use of novel social engineering techniques (39% of attacks). The report also found VIP users were specifically targeted in 25% of observed attacks. ClickFix, a social engineering technique designed to trick users into running malicious code themselves, continued to be a common vector carried over from 2025.

AI accelerates exploitation: React2Shell, LLM‑generated exploits and JadePuffer

Darktrace documents multiple ways AI is expanding the attacker toolkit. The firm observed threat actors using AI tools to generate malware and exploit code at scale — including an instance where an LLM produced working exploit code for the React2Shell vulnerability and the payload was deployed widely. In July, researchers highlighted what they described as the world’s first fully AI‑generated ransomware campaign, dubbed JadePuffer: an agentic threat actor exploited a vulnerability in an internet‑facing server and then launched a fully automated ransomware attack. "AI is accelerating the path from vulnerability disclosure to operational exploitation," the researchers wrote.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: Expect attackers to exploit identities, delegated access and legitimate admin tooling as primary vectors — detection strategies that focus only on malicious binaries or isolated indicators may miss coordinated misuse of trusted accounts and services.
  • Procurement leaders and developers: The Axios example and the abuse of blockchain services like those distributing AMOS and Phexia underline the systemic risk in widely used dependencies and third‑party services; dependency hygiene and vetting of service suppliers should be part of procurement conversations.
  • End users and executives: Phishing that passes DMARC, uses long contextual text, targets VIPs and leverages ClickFix techniques increases the chance that seemingly legitimate messages will succeed — authentication signals alone may no longer be a reliable indicator of safety.

Darktrace’s H1 2026 findings point to a common denominator: reliance on trust and delegation within cloud, SaaS and supply‑chain ecosystems can be weaponized by attackers who no longer need to "bypass" controls so much as inherit them. The examples in the report — from a single SaaS account enabling cross‑layer intrusions to the hijacking of a ubiquitous JavaScript library and the emergence of fully AI‑generated ransomware — sharpen a practical question for defenders: how do you detect and respond when the attacker arrives already armed with legitimate access? The report itself was published on August 3.

https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/