logo

How Adversaries Abuse Serverless Services to Harvest Sensitive Data from Environment Variables

ID: 92ec30f0-f5c8-556e-9439-9c60ba973a16

STIX ID: report--92ec30f0-f5c8-556e-9439-9c60ba973a16

Feed Name: Cloud Chronicles

Threat Score
60/100

Date Published: 2024-12-11

Date Updated: 2026-07-29

Author: The Permiso Team

...
...

This report explains how storing secrets in serverless environment variables (AWS Lambda, Azure Functions, GCP Cloud Functions, and Kubernetes) can be abused by attackers to harvest credentials, escalate privileges, and achieve persistent execution; it cites the Denonia malware targeting Lambda and demonstrates how cloud-offensive tools like Pacu and Cloudfox can enumerate and exfiltrate environment secrets, and it provides detection, mitigation and secret-management recommendations (Secrets Manager, Vault, Key Vault, Secret Manager, Kubernetes Secrets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.