Ransomware groups are increasingly shifting their focus from traditional on-premises systems to cloud infrastructure, specifically targeting backup systems and cloud management credentials. Google’s Security Chief highlighted that attackers are compromising backup data, deleting routines, and altering permissions to prevent recovery and increase ransom leverage, with compromised credentials and misconfigurations being the leading causes of breaches. The threat is particularly acute in regions with uneven digital maturity, such as APAC, where inconsistent security practices make organizations more vulnerable. Investigations have revealed that ransomware actors are now stealing AWS keys to gain access to cloud environments, further complicating incident response and expanding the attack surface. Both Google and security vendors are urging organizations to adopt isolated recovery environments and strengthen cloud credential management to mitigate these evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Varonis published research describing a ransomware intrusion pattern in which attackers steal AWS access keys to expand access and progress their operations in cloud environments. The reference provided does not include earlier dated milestones, so this event is anchored to the publication date.
Google Cloud CISO Phil Venables warned that ransomware groups increasingly target backup infrastructure, emphasizing that organizations should harden and isolate backups as part of resilience planning. The reference does not describe a specific incident date, so the event is anchored to the article publication date.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.