Massive AWS Extortion Campaign Hits 110K Domains! 💥

Summary:

  1. Extortion Attack
    A sophisticated extortion scheme has targeted 110,000 domains by exploiting misconfigured AWS .env files. Attackers replaced S3-stored data with ransom notes.

  2. Exploited Vulnerabilities
    The campaign involved scanning for exposed cloud access keys, using API calls to enumerate IAM users, and escalate permissions via newly created IAM roles.

  3. Automated Scanning
    Attackers employed AWS Lambda functions for automated scanning, highlighting advanced tactics in their operation.

Read more at: The Register

1 Like