The malware didn’t come from a sketchy server in a bulletproof-hosting jungle. It came from Blogspot.

That’s the uncomfortable detail buried in a new campaign researchers at Securonix are calling Veil#Drop, and it’s a good excuse to talk about a blind spot most cybersecurity programs still have: the assumption that a well-known domain is a safe domain. It isn’t. It’s just a domain your web filter doesn’t flag, which to an attacker is even better than safe.

Blogspot Became A Delivery Platform

Veil#Drop uses compromised legitimate websites alongside Blogspot pages to stage and serve payloads, chained through PowerShell and fileless execution techniques, ultimately dropping the PureLog information stealer. None of that requires exotic infrastructure. It requires a free Blogspot account, a bit of obfuscation, and the knowledge that most organizations don’t inspect traffic to Google-owned domains the way they inspect traffic to a domain registered last week in a country they’ve never done business with.

Security researchers analyzing malware delivery infrastructure
Veil#Drop abuses trusted hosting platforms to slip payloads past domain-reputation filters.

Fileless techniques matter here too. If the payload never touches disk as a discrete file, your endpoint tooling has less to hash, less to quarantine, and less to alert on. Combine that with a hosting domain your proxy already trusts, and you’ve built something closer to a keyless door than a lock someone has to pick.

IT Providers Are The New Front Door

Check Point Research just attributed a previously undocumented modular C2 framework, dubbed Cavern, to an Iran-linked cluster tied to Iran’s Ministry of Intelligence and Security. The targets: Israeli IT providers and government organizations. Notice the ordering. IT providers aren’t the prize. They’re the hallway.

Compromise a managed service provider or an IT vendor and you inherit whatever trust relationship that vendor has with its downstream clients, often including remote access, admin credentials, and software deployment pipelines nobody outside the vendor ever audits closely. It’s the same logic as the Blogspot trick, just applied to organizations instead of domains. The attacker isn’t breaking your defenses. They’re walking through a relationship you already vouched for.

This pattern isn’t isolated to Iran-linked operators, either. The BusySnake infostealer campaign tied to the Armored Likho cluster, hitting government and power-sector targets across Russia, Brazil, and Kazakhstan, leans on the same basic principle: blend in with legitimate-looking activity long enough that nobody bothers to look twice.

Trust Is Not A Control

Domain reputation, vendor allowlists, and “it’s from a big platform so it’s fine” heuristics are convenience decisions, not security controls. Treat them that way and you can still get value out of them while building real threat detection underneath.

Some concrete moves, ordered from immediate to ongoing:

  • Enable PowerShell script block logging and constrained language mode where feasible; fileless attacks live in that gap most orgs never instrument.
  • Inspect outbound traffic to trusted platforms (Blogspot, GitHub, cloud storage, pastebin-style sites) for content and behavior, not just destination reputation.
  • Apply brute-force protection and rate limiting on every externally reachable admin or remote-access interface your IT vendors use to touch your network.
  • Segment vendor and MSP access so a single compromised provider credential doesn’t equal domain-wide reach; least privilege applies to partners too.
  • Build incident response playbooks that assume the initial foothold arrived through a trusted channel, not an obviously malicious one.

None of this replaces firewall rules or endpoint tools. It supplements them with the assumption that attackers will actively route around whatever list you’ve built.

Security hardening in this context means treating “trusted” as a starting hypothesis, not a conclusion. Defense in depth was always meant to handle exactly this scenario: one layer gets fooled, another layer catches the behavior anyway. Reputation-based filtering is a fine first layer. It just can’t be the only one, because reputation is precisely the thing attackers have learned to borrow.

Illustration representing a modular command-and-control framework
Cavern’s operators went after IT providers first, government targets second.

The two campaigns aren’t related in origin or motive. One’s a criminal stealer operation, the other a state-linked espionage cluster. But they arrived at the same tactic independently, which is usually a sign the tactic works. When two unconnected threat actors converge on hiding inside trust relationships, that’s not a coincidence worth ignoring. It’s a design flaw in how most organizations still draw the line between “safe” and “unsafe” traffic.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.