The indicators are disappearing: intrusions are moving onto infrastructure you cannot block
Across four separate 2026 investigations, operators used legitimate cloud storage for command and control, one-time infrastructure per victim, and tooling already present on the host. The atomic indicator is becoming a wasting asset.

Four ways the indicator is being removed
Detection engineering rests on an assumption that is quietly failing: that an intrusion leaves something distinctive enough to write a rule against. Four investigations published in 2026, by four vendors, against four unrelated actors, show the same erosion from different angles.
The first is infrastructure that cannot be blocked. Trellix reports that APT28 used filen.io, a legitimate cloud storage service, for command and control, with the stated effect of making malicious traffic blend with normal user activity across encrypted channels and multiple compromised accounts [1]. Mandiant records UNC3753 delivering commands and links through Privnote, a self-destructing message service, specifically so that no permanent footprint remains, while remote access ran over Zoom, Microsoft Teams, Quick Assist and commercial remote monitoring tools including AnyDesk, Bomgar and Zoho Assist [4]. Blocking any of these means blocking a service the business uses.
The second is infrastructure that is never reused. Unit 42 reports that Screening Serpens provisioned three to five unique domains per target and per malware variant, mostly hosted on Azure, explicitly to prevent cross-contamination between victims and increase resilience [2]. A shared indicator is only useful if it is shared. Per-victim infrastructure means the domain extracted from one incident protects nobody else, and the feed it is published to is already stale.
The third is telemetry that is switched off before anything happens. Screening Serpens used AppDomainManager hijacking, manipulating legitimate XML configuration files to disable .NET security mechanisms including Event Tracing for Windows ahead of payload execution [2]. That is not evasion of a detection; it is removal of the sensor. The same report notes artificial file inflation to roughly 12 MB to push samples past sandbox scanning limits [2].
The fourth is living on what is already installed. Cisco Talos describes a ransomware cluster conducting reconnaissance through the firewall management centre's own legitimate utilities before establishing SOCKS5 proxies and reverse SSH tunnels [5]. Unit 42 records operators in Latin America running self-hosted tooling and living-off-the-land utilities [9]. Rapid7 describes a kernel-level implant in telecommunications networks that opens no listening port and does not beacon, concealing commands inside encrypted HTTPS traffic through abuse of SSL termination, with services masquerading as legitimate management components [6].
The detection data already reflects it
Mandiant's M-Trends 2026, drawn from more than 500,000 hours of investigation, puts internal detection at 52% of cases, external notification at 34% and adversary notification at 14% [7]. In ransomware cases the split inverts: adversary notification accounts for 44%, internal identification 41% and external notification 15% [7]. In close to half of ransomware incidents, the organisation learns it is compromised when the operator tells it.
Global median dwell time rose to 14 days in 2025 from 11, and to 122 days for cyber espionage groups, with some intrusions persisting over a year [7]. Dwell time rising while detection tooling budgets rise is the measurable form of the argument above.
Unit 42's 2026 incident response data points at what the intrusions actually turn on: identity weaknesses played a material role in close to 90% of investigations, 99% of cloud users, roles and services carried excessive permissions, and 87% of intrusions spanned two or more attack surfaces with 43% spanning four or more [8]. None of those are indicator problems.
Group-IB records the same movement on the criminal side. Publicly advertised network access fell 27% in 2025 as premium credentials moved into private channels, and 83% of cases involved data exfiltration [10]. What is bought and sold has moved out of view, and what is stolen no longer requires a payload that antivirus can catch.
The AI layer follows the same logic
The Google Threat Intelligence Group's September 2026 tracker records a PRC-nexus actor it tracks as UNC6508 deploying local language models inside victim infrastructure specifically to avoid API-side monitoring [3]. The reasoning is identical to per-victim domains and self-destructing messages: remove the observation point rather than defeat the detection at it. GTIG also records trojanised MCP servers targeting AI coding assistants, and a credential stealer that embeds prompt-injection text intended to make LLM-based security scanners fail [3].
Anthropic's September 2026 reporting describes financially motivated operators compromising SaaS providers in order to reach downstream customer data [11], which is the supply-chain version of the same move: operate inside a trust relationship the target cannot revoke without stopping work.
What still works
Three categories survive, and they are the ones worth funding.
- Identity and authorisation. Every case above ends in credential or session abuse, and Unit 42 puts identity in the causal chain of close to 90% of intrusions with near-universal excessive permission [8]. Permission scope is not an indicator that can be rotated away by the attacker.
- Behavioural and relational detection. Mass file search and download in a document management system, a proxy or tunnel process on an appliance, an outbound flow from a server workload to a consumer file-sharing domain: none of these depend on knowing the domain in advance [4][5][1].
- Sensor integrity as a monitored condition. If ETW can be disabled by a configuration file before execution [2], then the state of the sensor is itself security-relevant telemetry. Alert on logging stopping, not only on what logging reports.
What to do
- Baseline outbound access from server workloads to consumer cloud storage and paste or note services. Personal file-sharing traffic from a domain controller or a build agent is anomalous regardless of the destination's reputation [1][4].
- Treat indicator feeds as corroboration, not coverage. Per-victim infrastructure [2] means a clean feed match proves nothing about whether you are compromised.
- Monitor for telemetry gaps. Log the disabling of ETW, agent stops, and unexpected changes to .NET or application configuration files [2].
- Inventory and constrain remote access tooling. Mandiant recommends blocking unauthorised remote monitoring utilities through application control and restricting interactive screen control in authorised platforms [4].
- Rehearse the case where the adversary tells you. Adversary notification is 44% of ransomware detection [7]; the first hour of that path should be a practised procedure, not an improvisation.
- Reduce permission scope before buying more detection. A 99% excessive-permission rate [8] sets a ceiling on what any detection investment can achieve.
Domain view
None of this is new tradecraft in isolation. Living off the land, legitimate-service C2 and disposable infrastructure have all been documented for years. What the 2026 reporting shows is that these have stopped being the sophisticated end of the distribution and become the default, across state espionage, ransomware affiliates and commodity crime alike.
The consequence for a defender is a change in what to buy. An indicator-led programme is now measuring an adversary's willingness to reuse infrastructure, which the better-resourced ones no longer do. The controls that still bind are identity scope, behavioural detection, and knowing when your own sensors stop reporting.
There is a regional edge to this. Trellix's APT28 campaign concentrated on transport and logistics operators at 35% of targets alongside defence ministries at 40% [1], and Rapid7's telecommunications implant was built for subscriber tracking through signalling protocols [6]. Ports, carriers and logistics operators are heavily represented in Malaysian and wider ASEAN critical infrastructure, and they are precisely the sectors where legitimate remote access to operational systems is routine and therefore hardest to distinguish from an intrusion.
Sources
Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.
- APT28's Stealthy Multi-Stage Campaign Leveraging CVE-2026-21509 and Cloud C2 Infrastructure Trellix · 2026
- Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns Unit 42, Palo Alto Networks · 2026-05-22
- GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI Google Threat Intelligence Group · 2026-09-08
- Ongoing Targeted Campaign Against US Law Firms (UNC3753) Mandiant / Google Threat Intelligence Group · 2026-06-05
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos · 2026-09-09
- Rapid7 Labs Identifies State Sponsored Sleeper Cells Embedded in Global Telecommunications Networks Rapid7 · 2026-03-26
- M-Trends 2026 Report: Executive Edition Mandiant / Google Cloud · 2026
- 2026 Unit 42 Global Incident Response Report Unit 42, Palo Alto Networks · 2026-02
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Unit 42, Palo Alto Networks · 2026-09-03
- Ransomware in 2026: Same Business, New Rules Group-IB · 2026-07-23
- Countering misuse of AI: September 2026 Anthropic · 2026-09
Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: this article draws a pattern across separate vendor investigations with different visibility, scope and reporting periods; the campaigns described are not connected to one another and no common actor is implied. Attribution and tracking names are the assessments of the named researchers, not independent R3KONX findings. Corrections to event@r3konx.asia.
