216.73.216.226

Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments

· Published 16/08/2024 08:08 · Modified 16/08/2024 08:20

Export JSON

Essential information

Published
16/08/2024 08:08
Modified
16/08/2024 08:20
Tags
2024-08-16 automation aws cloud compromised credentials extortion scanning
Related entities
2 vulnerabilities (cve), 37 observables, 6 techniques (mitre)

Description

Unit 42 researchers uncovered an campaign that and extorted multiple victim organizations by leveraging exposed environment variable files containing sensitive . The campaign involved setting up attack infrastructure within victims' Amazon Web Services () environments and over 230 million targets for sensitive data. It targeted 110,000 domains, resulting in over 90,000 unique variables, including 7,000 service and 1,500 social media account . The attackers used Tor for reconnaissance, VPNs for lateral movement and data exfiltration, and VPS endpoints. They automated various tactics, indicating advanced skills.

External references