216.73.216.233

Cloud Abuse at Scale

· Published 01/11/2025 10:24 · Modified 03/11/2025 12:13

Export JSON

Essential information

Published
01/11/2025 10:24
Modified
03/11/2025 12:13
Tags
2025-11-01 aws bec cloud infrastructure coroxy credential abuse identity compromise portainer ses systembc trufflehog trufflenet xmrig
Related entities
2 techniques (mitre), 3 malware, 1 others

Description

A large-scale attack infrastructure dubbed has been identified, built around the open-source tool . This infrastructure is used to systematically test compromised credentials and perform reconnaissance across environments. The campaign involves over 800 unique hosts across 57 distinct Class C networks, characterized by consistent configurations and the use of . Alongside , adversaries are exploiting Amazon Simple Email Service () to facilitate Business Email Compromise () campaigns. The attackers create email identities using compromised WordPress sites and conduct aggressive cloud reconnaissance. This activity highlights the evolving tactics of threat actors in exploiting at scale, combining credential theft, reconnaissance automation, and abuse to conduct high-volume fraud with minimal detection.

External references