216.73.216.226

Virtual Infrastructure Abuse leads to SaaS Hijacks

· Published 27/08/2025 16:22 · Modified 27/08/2025 19:43

Export JSON

Essential information

Published
27/08/2025 16:22
Modified
27/08/2025 19:43
Tags
2025-08-27 hyonix inbox rules phishing saas compromise session hijacking vps abuse
Related entities
9 techniques (mitre)

Description

This analysis examines a series of coordinated SaaS account compromises across multiple customer environments, involving suspicious logins from VPS-linked infrastructure followed by unauthorized inbox rule creation and deletion of -related emails. The attackers leveraged virtual private servers (VPS) from providers like to bypass geolocation-based defenses, evade IP reputation checks, and blend into legitimate traffic. Key tactics included , inbox rule manipulation, and attempts to modify account recovery settings. The incidents highlight the growing abuse of VPS infrastructure in stealthy, scalable attacks targeting SaaS platforms.

External references