Darktrace has identified a wave of coordinated SaaS account compromises linked to the abuse of Virtual Private Server (VPS) infrastructure, uncovering tactics that allowed attackers to conceal phishing activity and bypass traditional security defences.
In a blog on the company’s site, Darktrace notes that the incidents, observed across multiple customer environments, involved suspicious logins from VPS-linked endpoints, followed by the creation of unauthorised inbox rules and the deletion of phishing-related emails.
According to Darktrace, these consistent behaviours point to a targeted campaign leveraging virtual infrastructure for both access and concealment.
A Virtual Private Server (VPS) is a virtualised server that gives users dedicated resources and control on shared hardware. While long relied upon by developers and businesses, VPS services are increasingly exploited by threat actors to launch stealthy, scalable attacks.
Darktrace noted that VPS abuse has become a growing trend in SaaS-focused campaigns. Such infrastructure enables attackers to bypass geolocation-based defences by mimicking local traffic, evade IP reputation checks with newly provisioned IP addresses, and blend into legitimate user behaviour.
In May 2025, Darktrace’s Threat Research team conducted an investigation into incidents across its customer base that were linked to VPS infrastructure. A fleet-wide review of alerts associated with Hyonix (ASN AS931) revealed a spike in anomalous activity beginning in March, including brute-force attempts, unusual login behaviour, and inbox rule creation tied to phishing campaigns.
Two customer networks stood out in particular. In one case, two internal devices showed mirrored compromise patterns, with rare endpoint logins, inbox manipulation, and the deletion of phishing-related emails. Darktrace traced the activity back to Hyonix infrastructure.
In another case, coordinated logins originated from IPs linked to multiple VPS providers, including Hyonix. Attackers then created inbox rules with obfuscated names and attempted to alter account recovery settings, indicating a broader, coordinated campaign.
Initial Intrusions
On 19 May 2025, Darktrace observed two devices in one customer network initiating logins from rare external IPs associated with VPS providers Hyonix and Host Universal, accessed via Proton VPN. These logins occurred within minutes of legitimate user activity from distant geolocations, suggesting session hijacking.
This triggered the Darktrace / IDENTITY model “Login From Rare Endpoint While User Is Active”, designed to highlight potential credential misuse where simultaneous logins occur from both familiar and unusual sources.
Shortly afterwards, the attacker deleted emails referring to invoice documents from a “Sent Items” folder, suggesting an attempt to conceal phishing emails sent from the compromised account. Although not directly observed, Darktrace suggested that initial access was likely achieved via phishing or account hijacking.
In a second customer environment, login activity was traced to Hyonix and other VPS providers including Mevspace and Hivelocity. Multiple users logged in from rare endpoints, with Multi-Factor Authentication satisfied via token claims—further reinforcing the likelihood of session hijacking.
Persistence and Inbox Manipulation
Following the initial compromise, attackers established persistence through the creation of new mailbox rules, often with minimal or obfuscated names to avoid detection during routine checks.
One rule targeted messages with subject lines referencing a document shared by a senior figure at the organisation, automatically deleting them. This pointed to an attempt to obscure malicious mailbox activity from legitimate users.
Across multiple environments, mirrored activity suggested a coordinated campaign. Three users saw nearly identical inbox rules created, while another had rules targeting fake invoice emails.
Darktrace also observed attackers attempting to escalate privileges. In some cases, this involved modifying account recovery settings, resetting passwords, or updating security information from rare external IPs.
What’s The Broader Network Impact?
The company reported further signs of malicious activity, including outbound spam with finance-related subject lines such as “INV#. EMITTANCE-1”. At the network level, Darktrace / NETWORK detected DNS requests to a suspicious domain showing signs of domain fluxing—a tactic where IP resolutions change frequently to avoid blocklists.
Recommended reading
- Security Leaders: Detection Alone Can’t Stop Cyber-threats
- Is Automation Fuelling a New Era of Cyber-crime?
- New Ransomware Gangs Drive Surge in Attacks
Darktrace also identified a device writing SplashtopStreamer.exe, associated with the remote access tool Splashtop, to a domain controller. While commonly used in IT support, its presence suggested the attacker may have deployed it for persistent access or lateral movement within the network.
Darktrace concluded that these incidents highlight the increasing abuse of VPS infrastructure in SaaS-targeted compromise campaigns. The company said threat actors are taking advantage of low-cost, anonymous hosting services to hijack accounts, launch phishing attacks, and manipulate mailbox configurations – often slipping past traditional security controls in the process.





