logo

SLTT Traffic Directing to S3 Buckets Hosting KrustyLoader

ID: 0205c297-bc64-5365-b4f7-fcd094983340

STIX ID: report--0205c297-bc64-5365-b4f7-fcd094983340

Feed Name: CISecurity.org Insights Blog

Threat Score
80/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

**CIS CTI identified KrustyLoader hosted on multiple AWS S3 buckets delivering an encrypted Sliver implant that is decrypted in-memory, injected into explorer.exe, and deletes its on-disk binary; analysis recovered embedded AES keys, stage-2 S3 URLs, Sliver C2 domains, and numerous IOCs.** The campaign leverages abused legitimate cloud storage to evade filtering and has been delivered via exploitation of internet-facing appliances (Ivanti, SAP NetWeaver, ScreenConnect, TeamCity); CIS notified affected MS-ISAC members and reported buckets to AWS for takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.