Abusing Cloud Services to Establish Covert Channels in Secure Enterprise Environments
Kotaiba Alachkar (TU Delft - Technology, Policy and Management)
Eduardo Barbaro (TU Delft - Technology, Policy and Management)
Cristiano Giuffrida (Vrije Universiteit Amsterdam)
Michel Van Eeten (TU Delft - Technology, Policy and Management)
Yury Zhauniarovich (TU Delft - Technology, Policy and Management)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
Threat actors have extensively used cloud services as covert channels for Command & Control (C2) and data exfiltration. In response, best practices for enterprise security recommend blocking unsanctioned cloud services and monitoring egress traffic to detect data exfiltration. In this paper, we demonstrate that these defenses fail in the context of first-party services offered by major Cloud Service Providers (CSPs), such as Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). To provide their services, CSPs require enterprise clients to create broad network openings to some of their services, which means that blocking access to other tenants' resources for those services is not possible. Additionally, their tight integration into enterprise IT means large volumes of traffic move from the enterprise to the cloud services, making it difficult to distinguish malicious from legitimate activity.To demonstrate the extent of this threat, we implement practical covert C2 channels through six first-party services across Azure, AWS, and GCP. Our simulated attacks demonstrate successful data exfiltration despite mature enterprise-level security controls. These attacks are both stealthy (i.e., evading OS-level and network-level detection) and effective (i.e., achieving practical exfiltration rates of over 400 Mbps). To complement our technical evaluation, we conducted a focus group study with security professionals. Participants acknowledged that awareness of this threat has recently increased, although it remains largely limited to the security experts inside enterprises. They also agreed that detecting such attacks is extraordinarily difficult. Our findings highlight a systemic blind spot in enterprise security and call for coordinated mitigation efforts between CSPs and developers of third-party enterprise services.
Files
File under embargo until 30-01-2027