State-sponsored cyber espionage has emerged as one of the biggest security threats due to the rise in geopolitical tension and the reliance on cloud infrastructure for strategic, military, and economic areas by governments and crucial companies. State-sponsored cybercrime, unlike traditional financially motivated crime, is characterized by greater funding, longer persistence, and sophistication. This paper examines how widespread adoption of cloud infrastructure intersects with this increase in crime, evaluates the risks posed as well as the benefits. The recent BRICKSTORM backdoor is used as an example of how such attacks occur and where the weaknesses lie. While cloud computing improves security through regular patches, standardized systems, and identity management, it also widens the attack surface and incentivizes attackers to target cloud providers directly. This paper finds that the widespread adoption of cloud infrastructure will decrease the likeliness of small-scale intrusions but will increase the severity and impact of state-sponsored operations.
Introduction
State-sponsored cyber espionage is a cybercrime operation funded and or run by the government of a nation who infiltrates networks, steals intelligence, intellectual property, and commercial data. Unlike traditional cybercrime whose crimes are typically executed for monetary value, state-sponsored cyber espionage is not, which in turn means that these operations exceed their civilian counterparts in persistence, resources, scope, and sophistication (Shloman, 2025). At this point in time, geopolitical tension has been at its highest point since the end of the Cold War. The United States and China are squaring off in the pacific and pull at economic strings while competing for dominance. Europe is at a crossroads and war rages in Donbas. New players like India can sway regional control. Wars today are not only fought on the frontlines but also in the digital space that is so heavily relied upon for not only military intelligence but also supply logistics and industrial organization. The cloud, which was once small and complicated, is now large and highly integrated, greatly increasing the attack vector for cyberattacks (ExtraHop, 2025).
State-sponsored groups rely on supply chain compromises, identity theft, credential compromises, spies implanted within foreign tech, and exploits all in collaboration with one another to infiltrate systems. Due to the interconnected nature of governments and the private sector, no one is spared. According to Cloud Security Alliance (2024) a large portion of Fortune companies have been the targets of state-sponsored cyberattacks and successful attacks cost American companies alone billions from intellectual property theft on the yearly basis. The goal of this paper is to evaluate how cloud adoption and reliance coincide with the increase of state-sponsored cyber espionage and analyze how this threat will evolve as organizations around the world continue to expand their information technology infrastructure on primarily cloud-based networks within the next five years and what this means for the industry at large.
Traditional on-premises weaknesses
In traditional on-premises networks, which are still widely used today especially in government, defense, law, and certain enterprises, the main weaknesses are predictable which makes it easier for government-affiliated groups to attack. One such weakness is the reliance on Virtual Private Network (VPN) appliances, firewalls, and remote access gateways that often run outdated firmware. Having outdated firmware could mean that the new firmware that is available was released to patch a security issue. Although this is not always the case, it is a security issue that can easily be exploited. Government-affiliated threat actors can automatically scan for edge devices that are at risk due to this oversight. Once breached, meaning the perimeter is breached, the edge device can become a staging ground for further attacks. Zero-day vulnerabilities are often focused on since the affected devices and software may already have a patch which does not get applied immediately or automatically to new systems. This strategy lends itself well to exploiting edge devices which often lack endpoint detection and response and increases the threat by widening the attack vector to incorporate larger portions of the network.
Persistence and control
For state-sponsored cybercrime, accessing the network is not enough, controlling it is the end goal. For this, it is crucial to gain control over Active Directory and become domain admin. This strategy ensures two things, persistence and access. Persistence is achieved by installing custom software such as BRICKSTORM which is designed to survive patching and rotation of credentials and can be used to regain access after remediation actions have been taken (Constantin, 2025). Systems on location implement logging that records different categories such as events, device, server, and syslog. These logs are not typically all recorded together due to detection varying by vendors and platform. While the initial conclusion may be that these independent logging systems will inevitably overlap, this is often not the case. The lack of overlap and complete logs leaves ample room for threat actors to remain undetected for long periods of time, even surpassing years at a time. By running many different devices with different software, companies are forced to push patches manually often, which in turn slows the patching process which increases the time for threat actors to act and the probability that they succeed. These delays increasingly put the defender on the backfoot and enable greater action from attackers.
The cloud as attack surface
In a hybrid network within the cloud and onsite, a breach of an edge device will also pose a threat to cloud devices. Cloud credentials saved on the edge device enable access to more resources that the attackers can use to move laterally into different systems. Cloud environments increase the complexity of networks in terms of both network architecture and security configurations. The widespread nature of clouds increases the possibility for gaps and expands the attack vector significantly. One benefit of using the cloud is that many different resources can be interconnected, this makes it easy for users to use different applications and access shared resources. While this may seem intuitive, to threat actors it is a golden ticket. These connections act as highways from one resource to another. While the increased complexity of these networks may deter small-time would-be attackers working alone or in small networks, large-scale government-funded programs have the resources, time, and personnel to stage sophisticated attacks and exploit the weakness of the cloud which is its convenience.
As the cloud advances and its complexity grows, there are no shortages of new attack vectors and vulnerabilities to be exploited (Unit 42, 2023). The increased size means that more areas must be watched, which cannot always be done. The recent trend of Artificial Intelligence being widely implemented in every place possible further increases the convenience to users but increases the potential for disaster. AI entities often lack MFA which is a crucial security aspect to protect networks and systems. If AI is being used to detect problems in a network but is breached, operations may appear to continue as normal, the network has been hijacked and is in effect being controlled by an outside entity.
Cloud as a defense tool
When implemented properly, the cloud is a valuable tool in mitigating espionage due to the ability to isolate resources. This, however, requires careful planning and documentation to ensure proper design. Architects should focus on reducing the possibility of credential theft by implementing MFA across all accounts, removing passwords, rigorous checking for login anomalies, and restricting access to specific conditions. Cloud providers being large entities means that ample resources are available for pushing patches in fashionable times and decreasing the diversity of patches needed, meaning that systems are standardized. Logging must be thorough and should be kept for long periods of time to counter the long dwell time of attacks. AI can detect anomalies in logs that go unnoticed to the human eye. By keeping with a fully zero trust architecture, attackers are unable to elevate their privileges and find themselves locked out of resources. Smart segmentation limits the impact to separate areas. Reliance on the cloud decreases the threat from small actors but increases the severity of large-scale operations by government actors. Instead of targeting the users, actors will aim for the providers themselves, which has the potential to increase the scope of the attack.
Conclusion
In the long run, the adoption of the cloud will provide users more tools than before which when implemented properly can ensure their security from threats. However, the reliance on clouds means that the target on providers themselves increases which will incentivize large operations to focus their resources on them. While before, the user had more knowledge of their supply chain, they no longer do, which limits their choice in vendors. The affordable and agile model provided by cloud providers is tempting to users and reduces the skill curve needed to get into the game. Wide access and low skill are two things that can spell disaster on the low levels. While on the high level, dependence and overconfidence pose a massive risk. In five years, cybercrime sponsored by governments will increase, but personal loss will decrease due to a change in motives.
References
Constantin, L. (2025, September 24). Chinese spies had year-long access to US tech and legal firms. CSO Online. csoonline.com
Unit 42. (2023, April 18). Unit 42 Unveils Most "Expansive" Cloud Threat Research Yet: Cloud Threat Report Volume 7 Examines the Expanding Attack Surface. unit42.paloaltonetworks.com
Shloman, N. (2025). Blurring the Lines: How Nation-States and Cybercriminals Are Becoming Alike. Trellix. trellix.com
ExtraHop. (2025). 2025 Global Threat Landscape Report. extrahop.com
Cloud Security Alliance. (2024). Top Threats to Cloud Computing 2024 Report. cloudsecurityalliance.org