{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/google-cloud-sdk/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Google Cloud SDK","Azure CLI","AWS CLI","GitHub CLI","Kubernetes","DigitalOcean CLI","Oracle Cloud Infrastructure CLI"],"_cs_severities":["high"],"_cs_tags":["credential-access","cloud-security","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Google","Microsoft","Amazon","GitHub","DigitalOcean","Oracle","Cloud Native Computing Foundation"],"content_html":"\u003cp\u003eAdversaries frequently target cloud-native environments by exploiting legitimate CLI tools to exfiltrate session tokens and credentials. By executing commands such as 'az account get-access-token', 'gcloud auth print-access-token', or 'kubectl get secret', attackers can capture sensitive authentication material from a host's local session. When these actions target multiple cloud providers (AWS, GCP, Azure, GitHub, OCI, or DigitalOcean) within a short window, it strongly indicates malicious reconnaissance or automated credential harvesting rather than standard administrative tasks. This activity is critical to identify, as printed tokens can be used to pivot deeper into the cloud infrastructure, bypass MFA, or maintain persistence in the target environment. Detection engineers should baseline existing CI/CD pipelines to distinguish legitimate service-principal activity from interactive or unauthorized shell-based token access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established on the endpoint via remote shell, compromised RMM, or scheduled tasks.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the presence of cloud CLI tools (e.g., gcloud, az, aws, gh, kubectl) in the PATH.\u003c/li\u003e\n\u003cli\u003eThe attacker executes authentication-related commands within an interactive or scripted shell to output bearer tokens to stdout.\u003c/li\u003e\n\u003cli\u003eThe process is repeated for different cloud provider CLI tools installed on the same host.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the printed output (tokens, identity strings, or secrets) using redirection or terminal monitoring.\u003c/li\u003e\n\u003cli\u003eThe captured tokens are exported off-host for use in secondary authentication.\u003c/li\u003e\n\u003cli\u003eThe final objective is unauthorized cloud API access for data exfiltration, lateral movement, or environment takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful harvesting of cloud CLI tokens allows unauthorized actors to bypass local identity controls and gain persistent access to cloud resources. This can lead to massive data breaches, resource hijacking for cryptomining, or the disabling of security services within the target cloud environment. Affected sectors include any organization relying on hybrid or multi-cloud infrastructure and automated CI/CD processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for CLI-based token access on all developer and jump-host systems.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement the detection logic below to identify when users or systems interact with multiple cloud provider CLI tools in a 5-minute window.\u003c/li\u003e\n\u003cli\u003eAudit existing CI/CD runners and deployment scripts to establish an allowlist of service identities.\u003c/li\u003e\n\u003cli\u003eForce revocation and rotation of any credentials printed to stdout if unauthorized access is confirmed.\u003c/li\u003e\n\u003cli\u003eUtilize provider-console revocation (e.g., Azure Entra ID or GCP IAM) rather than relying on local CLI logout commands, as local logout does not invalidate tokens already captured by the attacker.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T13:10:49Z","date_published":"2026-09-18T19:08:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-multi-cloud-cli-token-harvesting/","summary":"Threat actors harvest cloud and container platform authentication tokens by abusing legitimate CLI utilities to output secrets to standard streams, which can be detected via anomalous multi-provider access patterns.","title":"Detection of Multi-Cloud CLI Token and Credential Harvesting","url":"https://feed.craftedsignal.io/briefs/2026-09-multi-cloud-cli-token-harvesting/"}],"language":"en","title":"CraftedSignal Threat Feed - Google Cloud SDK","version":"https://jsonfeed.org/version/1.1"}