Detection becomes more difficult because the attacker can shift payload staging across Google Drive, OneDrive, Discord links, paste services, VPS hosting, and DDNS domains without changing the underlying tactic. Defenders then need to focus on content patterns, script behaviour, and endpoint execution chains, not only on a single hosting provider or indicator set.
Why shared hosting changes the detection problem
When RAT delivery uses cloud storage, chat platforms, paste sites, VPS infrastructure, and DDNS, the hosting layer becomes fluid rather than distinctive. The same payload can move through services that look normal in isolation, which means simple provider blocking or single-indicator hunting rarely holds up for long.
That does not make the campaign invisible. It changes the defender's job from "which host delivered it" to "what behaviour followed delivery", especially script launch patterns, LOLBin use, archive unpacking, and the process chain that turns a link or file into execution.
Because the infrastructure is shared, compromise signals often sit in the handoff between delivery and execution, not in the host itself. A stable tradecraft pattern can survive many infrastructure swaps, so the detection value shifts toward content traits, download behaviour, and endpoint telemetry.
How attackers benefit from rotating cloud and public infrastructure
Shared services give attackers two practical advantages: they blend into traffic users already expect, and they lower the cost of rapid replacement. If one link is reported or removed, the operator can rebuild the same chain elsewhere without changing the malware family or the core delivery logic.
This also helps them fragment the trail. One stage may live in a document host, the next in a paste service, and the final payload on a VPS or DDNS name. Each layer may look ordinary on its own, but together they create a repeated delivery pipeline that is easier to operate than to attribute.
For defenders, that means the infrastructure set is often less important than the pattern of reuse across services: repeated file naming, similar redirect logic, recurring archive structure, identical script stagers, or the same execution parent process after download.
What defenders should watch instead of a single host
Effective coverage comes from correlating content, network, and endpoint evidence. Focus on unusual office or browser activity that leads into script engines, archive tools, or command shells, especially when the source is a freshly shared link or public hosting domain with low prior reputation.
Useful hunts include downloads that immediately precede PowerShell, mshta, wscript, rundll32, or similar execution paths; cloud-share URLs embedded in email or chat; and DDNS domains that resolve to short-lived hosting infrastructure. Those are not proof by themselves, but they are strong indicators that the delivery chain is being used as an access path, not just as benign storage.
Where possible, enrich alerts with URL reputation, file type, document macros, parent-child process trees, and any repeatable script artefacts. That gives analysts something more durable than a blocklist of hosts that the operator will replace anyway.
Risk and Threat Considerations
Shared cloud services and public hosting raise the cost of attribution and the cost of suppression. The defender has to assume the attacker can move laterally across services, which makes one-off takedowns, DNS blocks, or a single provider denylist only partial controls.
Failure mechanism: the campaign survives by moving the staging point while preserving the same execution behaviour, so detection that depends on a fixed infrastructure footprint loses fidelity as soon as the operator rotates links or hosts.
Impact: dwell time increases, repeated delivery attempts are harder to suppress, and analysts can miss the campaign if they focus on the host rather than the post-click or post-download execution chain.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1105 — Ingress Tool Transfer | RAT staging via public hosting is a delivery and transfer pattern. |
| T1027 — Obfuscated Files or Information | Shared hosts often carry packed or disguised payloads to evade scrutiny. | |
| T1071 — Application Layer Protocol | Public cloud links and hosting services can blend malicious delivery into normal web traffic. | |
| Recommendation — Map staged downloads to T1105 and hunt for transfer-to-execution chains. Inspect staged content for obfuscation and unusual packaging before execution. Correlate web delivery patterns under T1071 with endpoint execution telemetry. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Correlating delivery, download, and execution requires complete logging across layers. |
| Recommendation — Centralize and retain logs that connect URL access, file download, and process launch. | ||
| NIST CSF 2.0 | DE.CM-09 — Malicious Code Detected | Detection of RAT delivery depends on monitoring for payload behavior after retrieval. |
| Recommendation — Tune monitoring to flag malicious code behavior after cloud-hosted delivery. | ||
Practitioner Guidance
What to prioritise: build detections around the transition from delivery to execution, not around the hosting provider alone. If you can see the payload launch chain, you are much less dependent on whether the attacker used OneDrive, Discord, a paste site, or a rented VPS.
What to verify: confirm that email, web, proxy, DNS, and endpoint telemetry can be correlated on the same event window. The most useful evidence is usually the sequence, link access, file retrieval, child process creation, and any script or archive activity that follows.
Practitioner takeaway: treat shared infrastructure as a disposable transport layer. The durable detection opportunity is the repeatable behaviour that follows the link, not the link's current home.
Related resources from NHI Mgmt Group
- What happens when organisations rely on default permissions and public cloud services without hardening them?
- Why does PKI matter when public services move from manual verification to cloud and mobile delivery?
- What happens when FinTech systems rely on public cloud or weak partner interfaces?
- What happens when applications rely too heavily on cloud-specific add-on services in a multi-cloud design?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org