Global Security Map All Articles
Geopolitical Risk Intelligence

Renting the Enemy's Infrastructure: How Adversaries Are Turning Commercial Cloud Services Into Weapons Against America

By Global Security Map Geopolitical Risk Intelligence
Renting the Enemy's Infrastructure: How Adversaries Are Turning Commercial Cloud Services Into Weapons Against America

For decades, American cybersecurity doctrine has been organized around a relatively coherent premise: identify the adversary's infrastructure, map its behavior, and sever its access. The logic was sound when hostile actors operated from clearly attributable servers in identifiable jurisdictions. That logic is now eroding in ways that most detection frameworks have not yet absorbed.

A growing body of intelligence assessments and incident response data points to a structural shift in how sophisticated threat actors — state-sponsored and otherwise — are conducting operations against American government agencies, defense contractors, financial institutions, and critical infrastructure operators. Rather than building or commandeering their own technical infrastructure, these actors are renting it. They are purchasing compute time, storage, and networking capacity from the same major commercial cloud providers that underpin large portions of the American economy. The implications for detection, attribution, and response are severe.

The Camouflage That Money Can Buy

Commercial cloud platforms — the major hyperscalers that dominate global market share — are, by design, shared environments. Thousands of organizations operate simultaneously within the same physical and logical infrastructure, segregated by access controls and virtualization layers but ultimately co-resident. This architecture delivers enormous efficiency benefits. It also delivers an operational advantage to any actor willing to exploit the trust that legitimate cloud traffic inherently carries.

When a hostile intelligence service routes its exfiltration traffic through a reputable cloud provider's IP ranges, that traffic arrives at a target's perimeter wearing the digital credentials of a trusted vendor. Firewall rules configured to allow outbound connections to major cloud endpoints — a near-universal configuration in modern enterprise environments — will pass that traffic without inspection. Security information and event management systems trained to flag anomalies against known malicious indicators will find nothing to flag. The adversary is, functionally, invisible.

This is not a theoretical vulnerability. Incident response teams at major American cybersecurity firms have documented intrusion campaigns in which the entire command-and-control architecture — the mechanism through which attackers issue instructions to compromised systems and extract stolen data — was hosted on legitimate cloud infrastructure. In several documented cases, attribution was delayed by months precisely because investigators were initially reluctant to classify traffic to well-known commercial endpoints as hostile.

State Actors Leading the Adaptation

China's intelligence apparatus has been identified in multiple government advisories as an early and sophisticated adopter of cloud-based operational infrastructure. Groups assessed to be affiliated with the People's Liberation Army and the Ministry of State Security have been observed using cloud-hosted virtual machines as relay points, staging grounds for malware, and repositories for exfiltrated data. The operational benefit is clear: American investigators pursuing a thread that leads to a cloud provider's infrastructure face immediate legal and technical friction that does not exist when pursuing a server in a foreign datacenter.

Russian-affiliated actors have demonstrated comparable adaptability. Campaigns attributed to Russian intelligence services have used cloud storage buckets — sometimes created with stolen or fraudulently obtained payment credentials — to host malicious payloads that victim machines retrieve over encrypted channels indistinguishable from routine software update traffic. Iranian and North Korean actors, operating under tighter resource constraints, have shown particular creativity in exploiting free-tier cloud accounts to establish persistent footholds at minimal cost and with minimal attribution risk.

The pattern across all of these actors reflects a deliberate strategic calculation. The investment required to build and maintain dedicated hostile infrastructure — and to continuously rebuild it as defenders burn it down — is now less attractive than the operational security benefits of blending into commercial cloud traffic. Defenders have, in effect, made their own infrastructure into the adversary's preferred operating environment.

Where Detection Frameworks Are Failing

The core failure is architectural. Most enterprise security stacks were designed around the assumption that the boundary between trusted and untrusted traffic could be maintained by monitoring the identity of communicating endpoints. Cloud computing has made that assumption untenable. The IP address of a major cloud provider is simultaneously the address of a legitimate software-as-a-service platform, a startup's development environment, a federal agency's disaster recovery system, and — potentially — an adversary's command node.

Behavioral analytics offer a partial remedy. Monitoring for anomalous data volumes, unusual access timing, and atypical communication patterns can surface suspicious activity even when the traffic source appears legitimate. However, sophisticated actors have demonstrated awareness of these detection methods. They throttle exfiltration rates to mimic normal backup traffic. They schedule operations during business hours to blend into peak usage windows. They use encrypted channels with valid certificates to prevent payload inspection.

Cloud providers themselves occupy an uncomfortable position in this dynamic. Their terms of service prohibit malicious use, and many have established threat intelligence teams that work cooperatively with government agencies to identify and suspend hostile accounts. But the scale of cloud operations — millions of accounts, billions of transactions daily — means that malicious actors operating with reasonable operational discipline can persist for extended periods before triggering provider-side detection. Account creation using fraudulent identities, cryptocurrency payments, and frequent account cycling further complicate provider-side enforcement.

The Cascading Risk of Misplaced Trust

The strategic risk extends beyond individual intrusions. When adversaries successfully embed their operations within commercial cloud infrastructure, they create cascading vulnerabilities that compound over time. Stolen credentials harvested through cloud-hosted attacks enable further cloud-based operations, creating a self-reinforcing cycle of access and exploitation. Data exfiltrated through cloud channels may be processed and analyzed in cloud environments before being transmitted to foreign intelligence services, adding additional layers of obfuscation to the intelligence collection chain.

For American organizations that have migrated core operations to cloud environments — a category that now includes significant portions of the defense industrial base, the financial sector, and federal civilian agencies — the exposure is not abstract. The same infrastructure that delivers operational agility and cost efficiency is the infrastructure through which adversaries are conducting sustained collection against American interests.

The risk calculus is further complicated by the international nature of cloud infrastructure. Data transiting cloud networks may physically pass through servers in multiple jurisdictions, each with its own legal frameworks governing government access. Adversaries with influence over foreign regulatory environments can potentially compel cloud providers operating in those jurisdictions to facilitate access in ways that are entirely invisible to American customers.

Toward a More Honest Risk Assessment

Addressing this threat requires moving beyond the comfortable assumption that cloud adoption and security are compatible by default. They can be, but only with deliberate architectural choices that most organizations have not yet made.

Zero-trust network architectures — which treat every connection request as potentially hostile regardless of source — offer a more realistic baseline for cloud-heavy environments. Rigorous monitoring of data egress volumes and destinations, even to known-legitimate endpoints, can surface anomalies that endpoint-based detection misses. Closer collaboration between cloud providers and government threat intelligence functions, with clearer legal frameworks for information sharing, would improve collective detection capacity.

For policy makers and security professionals mapping the actual threat landscape, the most important recognition is this: the perimeter is no longer where it appears on the network diagram. Adversaries have moved inside the trusted zone. The map of hostile infrastructure now overlaps, in ways that cannot always be resolved, with the map of the commercial infrastructure American organizations depend on every day. Operating effectively in that environment demands a level of analytical precision — and institutional honesty about existing blind spots — that current frameworks have not yet delivered.