MITRE ATT&CK Technique
T1585.003Cloud Accounts
- First Reported
- Sep 22, 2026
- Latest Reported
- Sep 22, 2026
Official Description
Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for [Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) or to [Upload Tool](https://attack.mitre.org/techniques/T1608/002)s. Cloud accounts can also be used in the acquisition of infrastructure, such as [Virtual Private Server](https://attack.mitre.org/techniques/T1583/003)s or [Serverless](https://attack.mitre.org/techniques/T1583/007) infrastructure. Establishing cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers.(Citation: Awake Security C2 Cloud)
Creating [Cloud Accounts](https://attack.mitre.org/techniques/T1585/003) may also require adversaries to establish [Email Accounts](https://attack.mitre.org/techniques/T1585/002) to register with the cloud provider.
Creating [Cloud Accounts](https://attack.mitre.org/techniques/T1585/003) may also require adversaries to establish [Email Accounts](https://attack.mitre.org/techniques/T1585/002) to register with the cloud provider.
- Tactics
- Resource Development
- Platforms
- PRE
- Parent Technique
- T1585 · Establish Accounts
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Reported Context (1)
- Two Cloudflare accounts with connected API keys fronted and automated operation domains. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
MITRE ATT&CK (26)
Vendors (8)
Products (10)
Tools (3)
Industries (6)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.