EC2 Grouper Hackers Abusing AWS Tools to Attack With Compromised Credentials
ID: 6e1e1d09-794d-54b5-be33-054fb784d5b9
STIX ID: report--6e1e1d09-794d-54b5-be33-054fb784d5b9
Feed Name: cybersecurityNews.com
Researchers identified a sophisticated actor dubbed EC2 Grouper that uses compromised credentials and AWS tools (notably PowerShell and AWS APIs) to enumerate regions and instance types, create VPCs and internet gateways, and deploy patterned security groups (e.g., "ec2group", "ec2group1"). Observed across dozens of customer environments and likely focused on resource hijacking, the group's indicators are transient and hard to detect; recommended defenses include CSPM, anomaly detection, and strict least-privilege controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
