Attackers are increasingly targeting cloud logging platforms to evade detection and maintain persistent visibility into compromised environments.
The report highlights how critical services such as AWS CloudTrail and Google Cloud Logging, designed to provide comprehensive audit trails, are being actively abused by threat actors to manipulate, disable, or redirect logs, effectively “blinding” security teams while enabling stealthy post-compromise operations.
Cloud logging systems serve as the authoritative record of all actions performed within cloud infrastructures, feeding essential telemetry into SIEM, SOAR, and cloud security posture management (CSPM) tools.
However, this central role also makes them high-value targets. Unit 42 researchers identified two primary attack objectives: defense evasion, in which attackers disrupt or manipulate logging to avoid detection, and continuous visibility, in which adversaries reroute logs to attacker-controlled environments for ongoing reconnaissance.
One of the most straightforward evasion techniques is to stop log collection entirely. In AWS, attackers with sufficient privileges can invoke the CloudTrail StopLogging API to halt log delivery to S3 buckets immediately.
Similarly, in Google Cloud, adversaries can turn off logging sinks via logging.sinks.Update permission. This creates an instant visibility gap, preventing defenders from detecting malicious activity in real time.
Another common method is deleting log storage destinations. Attackers with permissions such as s3:DeleteBucket in AWS or logging.buckets.delete in Google Cloud can remove the storage locations where logs are archived. This not only disrupts ongoing logging but also destroys historical forensic evidence.
In some cases, attackers target the log routing layer itself by deleting CloudTrail trails or Google Cloud sinks, effectively severing the pipeline that delivers logs to storage.
More advanced techniques involve impairing logging by manipulating encryption keys. In AWS environments, attackers can modify the Key Management Service (KMS) key used to encrypt logs and then revoke access to that key.
As a result, CloudTrail fails to write logs due to encryption errors, even though configurations may appear intact. A similar approach is possible in Google Cloud באמצעות customer-managed encryption keys (CMEK), where altering key permissions can render logs inaccessible or unreadable.
Unit 42 also observed log poisoning attacks, where adversaries modify stored log files to remove or alter evidence of malicious activity. Since logs are often stored in JSON format within cloud storage, attackers with object-level permissions can download, edit, and overwrite log files.
Without integrity validation mechanisms, such as AWS CloudTrail log file integrity validation, these manipulations can go undetected and mislead incident response efforts.
Beyond evasion, attackers are leveraging logging systems for continuous visibility. By creating new log routing configurations or modifying existing ones, threat actors can redirect logs to attacker-controlled storage. For example, in AWS, adversaries can create a new CloudTrail trail pointing to their own S3 bucket.
At the same time, in Google Cloud, they can configure sinks to export logs externally. This allows passive monitoring of victim environments, including API activity, IAM changes, and data access patterns, without triggering traditional alerts.
The impact of these techniques ranges from complete loss of visibility to covert data exfiltration and long-term persistence. High-risk actions, such as log redirection and disabling logging, are strong indicators of malicious activity and often precede broader attacks.
To mitigate these risks, organizations must enforce strict access controls on logging resources, limit permissions for modifying trails and sinks, and secure storage destinations.
Built-in protections, such as AWS’s immutable 90-day event history and Google Cloud’s _Required log bucket, provide some resilience. However, custom configurations remain vulnerable if not properly secured.
The findings underscore a critical shift in attacker behavior: rather than avoiding logs, adversaries are actively manipulating the logging infrastructure itself.
As cloud adoption grows, securing the integrity and availability of logging services is becoming a foundational requirement for effective detection, response, and forensic investigation.
CISO & Security Leaders: Your next breach may not have a face. Join ISC2’s LIVE webinar, “Ghost in the Machine”
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…