Categories: Cyber Security News

VPS Servers Targeted by Hackers to Breach SaaS Accounts

Cybersecurity firm Darktrace has uncovered a sophisticated campaign where threat actors leveraged Virtual Private Server (VPS) infrastructure to compromise Software-as-a-Service (SaaS) accounts across multiple customer environments.

The investigation, conducted in May 2025, revealed coordinated attacks utilizing VPS providers, including Hyonix and Host Universal, to bypass traditional security controls and maintain persistent access to compromised email accounts.

Darktrace / identity model “login from rare endpoint while user is active”, which detects simultaneous logins from both a common and a rare source to highlight potential credential misuse.

VPS Infrastructure Enables Stealthy Attack Operations

Virtual Private Servers have become increasingly attractive to cybercriminals due to their ability to provide clean, newly provisioned infrastructure that evades IP reputation checks while mimicking legitimate local traffic.

The attackers specifically targeted VPS providers offering rapid deployment and minimal open-source intelligence (OSINT) footprint, making detection significantly more challenging for traditional security systems.

Timeline of activity for case 1 – unusual vps logins and deletion of phishing emails.

The campaign demonstrated sophisticated techniques, including session hijacking, where attackers gained access to accounts while legitimate users remained active from distant geographical locations.

This created “improbable travel” scenarios that triggered Darktrace’s behavioral detection models, particularly the “Login From Rare Endpoint While User Is Active” alert system.

Coordinated Campaign Across Multiple Environments

Darktrace’s Threat Research team identified two primary attack scenarios during their investigation.

In the first case, attackers accessed two internal devices through VPS-linked IP addresses, subsequently deleting emails from “Sent Items” folders that referenced invoice documents, likely concealing phishing emails sent from the compromised accounts.

Timeline of activity for case 2 – coordinated inbox rule creation and outbound phishing campaign.

The second case involved multiple users experiencing coordinated logins from rare endpoints associated with various VPS providers, including Mevspace and Hivelocity.

Following initial access, attackers created inbox rules with obfuscated names designed to automatically delete incoming emails, particularly those referencing documents shared by VIP personnel within the targeted organization.

The investigation revealed mirrored activity patterns across different user devices, suggesting a coordinated campaign utilizing shared infrastructure and standardized attack methodologies.

Attackers also attempted to modify account recovery settings and maintain persistence through various techniques.

Security Implications and Detection Challenges

The campaign highlights critical vulnerabilities in traditional security approaches that rely heavily on IP reputation and geolocation-based controls. VPS abuse enables attackers to blend into legitimate traffic patterns while maintaining anonymity and scalability in their operations.

Notably, Darktrace’s Autonomous Response capability was not enabled in the affected customer environments, preventing automated containment actions that could have halted the compromise during its initial stages.

The attacks coincided with legitimate user activity, rendering conventional security tools largely ineffective against these sophisticated techniques.

This investigation underscores the necessity for behavior-based detection systems capable of identifying subtle anomalies such as concurrent session activity, unusual login sources, and suspicious mailbox rule modifications that traditional rule-based security systems typically miss.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post VPS Servers Targeted by Hackers to Breach SaaS Accounts appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Overwhelmed by Your Tax Return? File With a TurboTax Expert for Just $150 Flat

The deadline to file your taxes is less than one month away, on April 15th.…

2 hours ago

Overwhelmed by Your Tax Return? File With a TurboTax Expert for Just $150 Flat

The deadline to file your taxes is less than one month away, on April 15th.…

2 hours ago

Director of One of 2024’s Best Games Says, “Expect the Unexpected” Ahead of Upcoming Reveal

The debut game from developer Sunset Visitor, 1000xResist, took us by surprise in 2024 and…

2 hours ago

An Introduction to the Strait of Hormuz and Its Role in the Longstanding US-Iran Conflict

Above, you can watch a primer on the Strait of Hormuz, the narrow passage between…

2 hours ago

Barn Shooting Arrests

INDIANAPOLIS, Ind. (WOWO) — Police have arrested two teenagers after gunfire was aimed at the…

2 hours ago

Barn Shooting Arrests

INDIANAPOLIS, Ind. (WOWO) — Police have arrested two teenagers after gunfire was aimed at the…

2 hours ago

This website uses cookies.