T1535

Unused/Unsupported Cloud Regions

IaaSnothing on this site yetT1535 on attack.mitre.org

Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud infrastructure. Cloud service providers often provide infrastructure throughout the world in order to improve performance, provide redundancy, and allow customers to meet compliance requirements.

MITRE ATT&CK 19.2, retrieved 2026-09-12

how MITRE says to see it

Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)

  • Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions.

what reduces it

  • M1054 Software Configuration. Cloud service providers may allow customers to deactivate unused regions.

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.