Command & Control infrastructure is commonly thought of as spun-up servers using known 'bad' or newly established domains and IP addresses. But what if the adversary uses common cloud storage services for the same purposes? We'll look at some real-world examples of APTs using this technique in the wild. We'll demo an open source tool that uses Dropbox as a Command & Control server and observe the network activity associated with this communication.