If I asked you what the common ways to exploit a cloud app for malicious purposes are, I bet your answer would probably be either to use it to distribute malicious content (such as malware or phishing pages), or to host the command and control (C2) infrastructure. In reality another frequent technique is the dead drop resolver, where a legitimate service is abused by threat actors to host the information related to the C2 infrastructure rather than the C2 infrastructure itself.
In this scenario the malware payload connects to the cloud application, and instead of contacting the command and control directly, it obtains the updated list of C2 servers where the connection can be eventually established. This makes the malicious infrastructure more resilient, since the attackers can dynamically update the list of C2 servers and easily switch across different instances, in case the original one is taken down.
In the latest example, discovered by researchers at Secureworks, the dead drop resolver technique has been leveraged by the Iranian government-sponsored COB