216.73.216.6

Tales from the cloud trenches: The Attacker doth persist too much, methinks

· Published 13/05/2025 21:01 · Modified 21/05/2025 19:34

Export JSON

Essential information

Published
13/05/2025 21:01
Modified
21/05/2025 19:34
Tags
2025-05-13 api-gateway aws cloud security iam identity-center lambda persistence telegram
Related entities
5 observables

Description

A leaked access key led to malicious activities over a 150-minute period, involving five distinct IP addresses. The attackers employed both common and innovative tactics, including creating '-as-a-service' infrastructure, manipulating Identity Center, and disabling organization-level services. Notable techniques involved creating functions for dynamic user creation, using for operations, disabling trusted access for services, and exploiting Identity Center for . The attack encompassed initial access, discovery, , credential access, and impact tactics, highlighting the need for enhanced measures and detection strategies.

External references