Blog
Cloud-targeted attacks conducted by TRIPLESTRENGTH operation
Summary: Google Cloud’s Threat Horizons research described TRIPLESTRENGTH, a financially motivated operation that combined cloud account hijacking, cryptocurrency mining and separate ransomware activity.
How the operation gained access
TRIPLESTRENGTH used stolen credentials and browser cookies—some obtained from infostealer logs—to enter victim cloud environments. The group initially abused compromised accounts to create compute resources for cryptocurrency mining. Later activity involved highly privileged accounts and changes to billing relationships that enabled larger unauthorized workloads.
Cloud abuse and ransomware
Google’s reporting connected the actor with access sales and attacks spanning several cloud providers. The group also participated in ransomware and extortion operations, although the researchers assessed that those activities were kept separate from its cryptomining campaigns. Reported ransomware families included LokiLocker, Phobos and RCRU64.
Why it matters
A valid cloud session can be more valuable than a password because it may bypass part of the normal login flow. Defenders therefore need visibility into identity, session and billing events—not only malware on endpoints.
Practical takeaway
- Require phishing-resistant multifactor authentication for privileged cloud accounts.
- Revoke sessions immediately when credentials or browser cookies may be exposed.
- Alert on new billing contacts, unusual compute creation and rapid resource expansion.
- Separate backup and logging permissions from day-to-day administration.
Original sources: SC Media — Cloud-targeted attacks conducted by TRIPLESTRENGTH operation; Google Cloud — CISO Insights Hub and Threat Horizons reports
Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.