{"id":11707,"date":"2026-03-25T13:13:59","date_gmt":"2026-03-25T13:13:59","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11707"},"modified":"2026-03-25T13:14:00","modified_gmt":"2026-03-25T13:14:00","slug":"an-analysis-of-cloud-infrastructure-utilization-in-malware-command-and-control","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/an-analysis-of-cloud-infrastructure-utilization-in-malware-command-and-control\/","title":{"rendered":"An Analysis Of Cloud Infrastructure Utilization In Malware Command And Control"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">An Analysis Of Cloud Infrastructure Utilization In Malware Command And Control<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In recent years, malware authors have increasingly favored using legitimate cloud platforms such as Telegram, Discord, Google Drive, and Dropbox as Command and Control (C2) channels. This tactic allows malware to evade traditional detection mechanisms and hide in normal user traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this paper, we analyze real-world malware campaigns that use cloud infrastructure as a control channel, focusing on how cloud APIs are used to steal data, download payloads, and send remote commands. We will present techniques for masking and evading detection, as well as why many current security products fail to detect this method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, we will present practical methods for detecting and mitigating these threats, including behavioral monitoring, anomaly detection, and threat hunting via cloud telemetry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article aims to raise awareness among users and enterprises of this growing trend and provide specific strategies to defend against malware that exploits cloud infrastructure.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Tran-Thi-Hieu-Ngan.png\" alt=\"\" class=\"wp-image-11708\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Tran-Thi-Hieu-Ngan.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Tran-Thi-Hieu-Ngan-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Tran-Thi-Hieu-Ngan-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Tran-Thi-Hieu-Ngan-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong><strong>Tran Thi Hieu Ngan &#8211; CMC Cyber Security<\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tran Thi Hieu Ngan is a Malware Researcher who began her career as a malware research intern in her third year at university. After earning her bachelor\u2019s degree, she pursued a professional path in malware research. Her work focuses on malware analysis, developing advanced detection and remediation technologies, and hunting advanced persistent threats (APT). She is committed to continuous professional development, building the expertise required to proactively safeguard against emerging cyber risks.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Bui-Huy-Anh.png\" alt=\"\" class=\"wp-image-11709\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Bui-Huy-Anh.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Bui-Huy-Anh-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Bui-Huy-Anh-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Bui-Huy-Anh-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong><strong><strong>Bui Huy Anh &#8211; CMC Cyber Security<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As Head of Anti-Malware Solutions Department, a senior cybersecurity expert with extensive experience in malware research and analysis, Bui Huy Anh plays a key role in researching cyber security threat, designing and implementing advanced security solutions for enterprises, aiming to develop CMC\u2019s comprehensive cybersecurity ecosystem, aligned with international standards and capable of responding to sophisticated threats.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back An Analysis Of Cloud Infrastructure Utilization In Malware Command And Control In recent years, malware authors have increasingly favored using legitimate cloud platforms such as Telegram, Discord, Google Drive, and Dropbox as Command and Control (C2) channels. This tactic allows malware to evade traditional detection mechanisms and hide in normal<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/an-analysis-of-cloud-infrastructure-utilization-in-malware-command-and-control\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11707","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11707"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11707\/revisions"}],"predecessor-version":[{"id":11710,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11707\/revisions\/11710"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}