{"id":6380,"date":"2025-08-23T10:03:36","date_gmt":"2025-08-23T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/23\/hackers-abuse-vps-servers-to-compromise-software-as-a-service-saas-accounts\/"},"modified":"2025-08-23T10:03:36","modified_gmt":"2025-08-23T10:03:36","slug":"hackers-abuse-vps-servers-to-compromise-software-as-a-service-saas-accounts","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/23\/hackers-abuse-vps-servers-to-compromise-software-as-a-service-saas-accounts\/","title":{"rendered":"Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts"},"content":{"rendered":"<p>    Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are increasingly leveraging Virtual Private Server (VPS) infrastructure to orchestrate sophisticated attacks against Software-as-a-Service (SaaS) platforms, exploiting the anonymity and clean reputation of these hosting services to bypass traditional security controls.<\/p>\n<p>A coordinated campaign identified in early 2025 demonstrated how threat actors systematically abuse VPS providers like Hyonix, Host Universal, Mevspace, and Hivelocity to compromise enterprise email accounts and establish persistent access to organizational systems.<\/p>\n<p>The attack methodology centers on session hijacking techniques, where attackers utilize compromised credentials to log into SaaS accounts from VPS-hosted infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjpOevDehNE3ZwWdzJ7Vnch_4tZpjwqFHihZEzjyckNTeoX7Y6n0VQMDFnLSYdidauiJZ2WsBhn7H-rRBY7c1qlUX1RSPO3z-tgHP7Rogua4y7HxrBO4sKe_hr5ngjZxoc4qNRW1EVODByMw9s9U3Bg7afMbPZ5RBkglabW6vPTlpSfS_FY70la9YVBuYo\/s16000\/Timeline%2520of%2520activity%2520for%2520Case%25201%2520-%2520Unusual%2520VPS%2520logins%2520and%2520deletion%2520of%2520phishing%2520emails%2520%28Source%2520-%2520Darktrace%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Timeline of activity for Case 1 \u2013 Unusual VPS logins and deletion of phishing emails (Source \u2013 Darktrace)<\/figcaption><\/figure>\n<\/div>\n<p>This approach allows malicious actors to circumvent geolocation-based <a href=\"https:\/\/cybersecuritynews.com\/strengthening-security-measures-in-digital-advertising-platforms-2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security measures<\/a> by appearing as legitimate traffic from trusted hosting providers.<\/p>\n<p>The clean IP reputation associated with newly provisioned VPS instances enables attackers to evade conventional blacklist-based detection systems, making their activities blend seamlessly with normal business operations.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg6rDL7uIR0rQWXtXq1eZnabICejaRTkBLnbmzzLnFyeJ_5TeeH0EfWCWa0SDYezs8BRsc6kxpJKug8GsfjFQExLrsBZafbtpygT5BQuKuStiKfgk-wkvMWxoMSqUoyDFRGtTzNq4y815NmsO-v3FVjuS4I2KbPELzkOXRpaz9c2-QXAXIfaZ7CMHGKQN0\/s16000\/Timeline%2520of%2520activity%2520for%2520Case%25202%2520%25E2%2580%2593%2520Coordinated%2520inbox%2520rule%2520creation%2520and%2520outbound%2520phishing%2520campaign%2520%28Source%2520-%2520Darktrace%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Timeline of activity for Case 2 \u2013 Coordinated inbox rule creation and outbound phishing campaign (Source \u2013 Darktrace)<\/figcaption><\/figure>\n<\/div>\n<p>Recent investigations spanning March through May 2025 revealed a surge in anomalous login activities originating from Hyonix\u2019s Autonomous System Number (ASN AS931), with threat actors demonstrating remarkable consistency in their attack patterns across multiple victim environments.<\/p>\n<p>Darktrace analysts <a href=\"https:\/\/www.darktrace.com\/blog\/from-vps-to-phishing-how-darktrace-uncovered-saas-hijacks-through-virtual-infrastructure-abuse\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> suspicious activities including improbable travel scenarios where users appeared to access accounts simultaneously from distant geographical locations, indicating clear signs of credential compromise and session hijacking.<\/p>\n<p>The campaign\u2019s sophistication extends beyond initial access, incorporating <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">Multi-Factor Authentication<\/a> (MFA) bypass techniques through token manipulation and the systematic creation of obfuscated email rules designed to maintain stealth.<\/p>\n<p>Attackers established persistence by creating inbox rules with minimal or generic names to avoid detection during routine <a href=\"https:\/\/cybersecuritynews.com\/strengthening-security-measures-in-digital-advertising-platforms-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">security audits<\/a>, automatically redirecting or deleting incoming emails to conceal their malicious activities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-persistence-and-evasion-mechanisms\"><strong>Advanced Persistence and Evasion Mechanisms<\/strong><\/h2>\n<p>The threat actors demonstrated advanced understanding of email security systems by implementing targeted inbox rule manipulation techniques that operate below the threshold of typical security monitoring.<\/p>\n<p>The malicious rules specifically targeted emails containing sensitive organizational information, including communications from VIP personnel and financial documents.<\/p>\n<p>Technical analysis revealed the use of MITRE ATT&amp;CK technique T1098.002 (Exchange Email Rules) combined with T1071.001 (Web Protocols) for command and control operations.<\/p>\n<p>Key indicators of compromise include IP addresses 38.240.42[.]160 and 194.49.68[.]244 associated with Hyonix infrastructure, alongside 91.223.3[.]147 from Mevspace Poland.<\/p>\n<p>The attackers employed domain fluxing techniques for infrastructure resilience while maintaining operational security through carefully timed activities that coincided with legitimate user sessions, effectively masking their presence within normal business communications.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-vps-servers\/\">Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-vps-servers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts Cybercriminals are increasingly leveraging Virtual Private Server (VPS) infrastructure to orchestrate sophisticated attacks against Software-as-a-Service (SaaS) platforms, exploiting the anonymity and clean reputation of these hosting services to bypass traditional security controls. A coordinated campaign identified in early 2025 demonstrated how threat actors systematically abuse VPS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6380","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6380"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6380"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6380\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}