logo

EC2 Grouper Hackers Abusing AWS Tools to Attack With Compromised Credentials

ID: 6e1e1d09-794d-54b5-be33-054fb784d5b9

STIX ID: report--6e1e1d09-794d-54b5-be33-054fb784d5b9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Researchers identified a sophisticated actor dubbed EC2 Grouper that uses compromised credentials and AWS tools (notably PowerShell and AWS APIs) to enumerate regions and instance types, create VPCs and internet gateways, and deploy patterned security groups (e.g., "ec2group", "ec2group1"). Observed across dozens of customer environments and likely focused on resource hijacking, the group's indicators are transient and hard to detect; recommended defenses include CSPM, anomaly detection, and strict least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.