INTEL_REPORT
Palo Alto Networks Unit 42 · published 5/22/2026, 10:00:24 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42 . Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Cloud Cybers…
https://unit42.paloaltonetworks.com/roadtools-cloud-attacks
sha256:42d5df49395642ec244c9a77944af438f8a74b7c4ad9ff30eeb013a272677087
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| domain |
| graph.microsoft.com |
| Open → |