A Familiar Cloud Tool Turned Into an Exfiltration Channel

When incident responders at Sygnia dug into a double extortion ransomware attack, they uncovered something that should concern anyone who relies on cloud storage for business operations: the attackers behind the intrusion, identified as the Vice Society ransomware group, had used Microsoft OneDrive as their primary channel for stealing corporate data. Rather than deploying custom exfiltration malware that might trip alarms, the threat actors leaned on a tool that nearly every organization already trusts and whitelists.

Double extortion has become the default playbook for major ransomware operations. Attackers don't just encrypt files and demand a ransom for the decryption key. They also steal sensitive data first, then threaten to leak it publicly if the victim doesn't pay a second time. This tactic has shown up repeatedly in recent incidents, including the ongoing LockBit 5.0 double extortion campaign that continues to hit organizations worldwide. What makes the Vice Society case notable is not the extortion model itself, but the method used to quietly move stolen data out the door.

Why Hiding Inside OneDrive Traffic Works So Well

Most enterprise security tools are built to flag unusual outbound connections, unknown IP addresses, or unrecognized applications reaching out to the internet. OneDrive doesn't trigger those alerts because it's a legitimate, widely deployed Microsoft service that security teams generally allow by default. By routing stolen files through OneDrive sync activity, Vice Society's operators were able to blend their exfiltration traffic with normal, everyday cloud usage.

This is the core lesson from Sygnia's forensic investigation: attackers increasingly succeed not by breaking new ground technically, but by abusing the trust organizations already place in mainstream platforms. It's a pattern that shows up elsewhere in the threat landscape too. A similar dynamic played out when malicious code hidden inside a compromised VS Code extension led to thousands of stolen repositories, again because a trusted developer tool was the vector rather than an obviously suspicious one. When the delivery mechanism looks routine, detection becomes far harder, and the window for attackers to operate undetected grows longer.

Luna Moth: A Different Threat, Same Corporate Data Focus

Sygnia's team also flagged a separate threat actor worth understanding on its own terms: Luna Moth. Unlike Vice Society's ransomware-and-leak approach, Luna Moth's tactics more closely resemble false subscription scams, the kind of social engineering that tricks victims into believing they've signed up for a recurring charge they need to cancel. But the end goal circles back to the same target that makes ransomware groups so dangerous: corporate data. Luna Moth uses that deceptive entry point to get access to sensitive business information, even without necessarily deploying encryption malware at all.

The distinction matters for defenders. Not every serious data theft incident looks like a classic ransomware attack with a ransom note and locked files. Some groups skip encryption entirely and go straight for extortion based on stolen data alone, which means security teams can't rely solely on detecting encryption behavior to catch an active breach.

What This Means For You

For IT and security teams, this case is a reminder that allowlisting a service like OneDrive isn't the same as securing it. Monitoring should extend to unusual volumes of data moving through approved cloud applications, not just unfamiliar destinations. Data loss prevention tools, anomaly detection tuned to cloud sync behavior, and strict access controls around who can move large amounts of data are all more relevant now than ever, especially as attackers refine their tactics the way AI is already reshaping ransomware operations, forcing managed service providers to rethink cyber recovery strategies entirely.

For individuals and smaller organizations, the takeaway is broader: encrypting sensitive files before they ever reach cloud storage, using strong authentication on cloud accounts, and staying skeptical of subscription-related emails or prompts can reduce exposure to both ransomware groups and social engineering plays like Luna Moth's. Encrypting traffic and data in transit, whether through a reputable VPN or built-in encryption tools, adds a layer of protection, though it won't stop an attacker who has already gained legitimate account access. Layered defenses, not a single tool, are what actually limit the damage.

Key Takeaways

  • Vice Society exfiltrated stolen data through OneDrive, exploiting the trust organizations place in mainstream cloud services rather than relying on custom malware.
  • Luna Moth operates differently, using tactics resembling false subscription scams to reach the same goal: corporate data theft.
  • Monitoring cloud app behavior for unusual data volume, not just unfamiliar destinations, is essential to catching this kind of exfiltration.
  • Double extortion remains the dominant ransomware model, meaning stolen data poses a risk even if backups allow you to avoid paying for decryption.
  • Encrypting sensitive data before it reaches the cloud and enforcing strong access controls reduces exposure regardless of which technique attackers use.

As ransomware groups continue finding ways to hide in plain sight, staying informed about how these techniques evolve is one of the simplest steps organizations and individuals can take toward better protection.