Attackers Have Dropped Brute Force for High-Trust Exploitation
Cloudforce One's 2026 threat research, drawn from trillions of network signals, points to a clear strategic evolution among adversaries: the brute force era is giving way to a model built on abusing trusted systems and relationships. The inaugural 2026 Cloudflare Threat Report details this shift and the tactics that now define the threat landscape.
The new attacker metric: Measure of Effectiveness
The report frames attacker decisions around the Measure of Effectiveness (MOE): the calculated ratio of effort to operational outcome. Attackers now favor throughput over complex, expensive one-off hacks. Why deploy an expensive zero-day when a stolen session token—an Identity-based attack—offers a higher MOE? Why build custom infrastructure when a reputation shield like LotX provides free, near-untraceable delivery? Why write code by hand when AI accelerates discovery and exploit development?
The result is that the most dangerous actors are not necessarily those with the most advanced code, but those who integrate intelligence and tooling into a continuous system that achieves its mission quickly.
Eight trends defining 2026
Cloudforce One's research identifies eight key trends, each driven by MOE calculations:
- AI automation accelerates attacker operations. Generative AI supports real-time network mapping, exploit development, and deepfake creation, enabling lower-skilled actors to run high-impact campaigns.
- State-sponsored pre-positioning targets critical infrastructure. Groups including Salt Typhoon and Linen Typhoon focus on North American telecom, commercial, government, and IT services, establishing presence for long-term geopolitical leverage.
- Over-privileged SaaS integrations expand blast radius. As seen in the GRUB1 breach of Salesloft, a single compromised third-party API can cascade into a breach affecting hundreds of distinct corporate environments.
- Trusted cloud services mask attacks. Adversaries exploit legitimate SaaS, IaaS, and PaaS tools—such as Google Calendar, Dropbox, and GitHub—to make malicious activity appear benign.
- Deepfake personas enter Western payrolls. North Korea has operationalized remote IT worker schemes, deploying deepfakes and fraudulent identities to embed operatives inside Western companies for espionage and revenue.
- Token theft neutralizes MFA. Infostealers like LummaC2 harvest active session tokens, letting attackers bypass multi-factor authentication entirely and move straight to post-authentication actions.
- Relay blind spots enable brand spoofing. Phishing-as-a-service exploit a gap where mail servers fail to re-verify sender identity, allowing high-trust brand impersonations to land directly in inboxes.
- Hyper-volumetric DDoS exhausts capacity. Massive botnets like Aisuru drive record-breaking distributed denial-of-service attacks, closing the window for human response.
Living off the land in the cloud
A standout high-MOE tactic is weaponized cloud tooling. Rather than operating from known malicious servers, attackers route command-and-control traffic through legitimate platforms—Google Drive, Microsoft Teams, Amazon S3—making their activity nearly indistinguishable from normal corporate traffic. The report documents this "living off the land" approach in detail.
SaaS platforms are also exploited for launching or scaling attacks. Services such as Amazon SES and SendGrid, intended for legitimate bulk email, are frequently abused for phishing and malware distribution.
| Threat Actor | Country | Technique | Details | Example |
|---|---|---|---|---|
| FrumpyToad | China | Logic-based C2 | Moving "inside the box" of reputable SaaS logic to evade detection. | Weaponizes Google Calendar for cloud-to-cloud C2 loop, reading and writing encrypted commands directly into event descriptions. |
| PunyToad | China | Encrypted tunneling | Utilizing legitimate developer tools to bypass egress filtering. | Uses tunneling capabilities and cloud computing to create resilient, living-off-the-cloud architectures, masking backend origin IPs and prioritizing long-term persistence. |
| NastyShrew | Russia | Paste site dead drop resolvers | Using public "paste" sites to coordinate shifting infrastructure. | Uses services like Teletype.in and Rentry.co as dead drop resolvers (DDR); infected hosts poll these sites to retrieve rotating C2 addresses. |
| PatheticSlug | North Korea | PaaS-ing the perimeter | Exploiting the "reputation shield" of cloud ecosystems to mask malicious delivery. | Used Google Drive and Dropbox to host XenoRAT payloads, leveraging GitHub for covert C2, successfully blending into legitimate enterprise traffic. |
| CrustyKrill | Iran | SaaS-hosted phishing | Blending credential harvesting into common cloud hosting. | Hosts C2 pages on Azure Web Apps (.azurewebsites.net) and uses ONLYOFFICE to host payloads, giving their operations a veneer of legitimacy. |
Research methodology: dogfooding AI and analyzing global telemetry
To unmask these trends, Cloudforce One applied its own tools to its own systems. In one case, an AI coding agent was tasked with a self-vulnerability analysis, uncovering CVE-2026-22813 (9.4 CVSS), a critical flaw in markdown rendering pipelines allowing unauthenticated remote code execution.
Telemetry analysis from the report reveals an email identity gap: nearly 46% of analyzed emails failed DMARC authentication checks, a surface area PhaaS bots are rapidly exploiting. DDoS research identifies a 31.4 Tbps baseline for attacks, 63% of all logins involve credentials already compromised elsewhere, and 94% of login attempts now originate from bots.
The shift to autonomous defense
With threats moving at machine speed, the report argues human-centric defense is no longer viable. It advocates a pivot to autonomous defense: systems that harden the connective tissue of networks, provide real-time visibility, and respond automatically to drive the adversary's MOE toward zero.
To support this shift, Cloudflare is evolving its threat events platform into a fully automated, visual command center for security operations.
Full findings, case studies, and tactical recommendations are available in the complete 2026 Cloudflare Threat Report.



