New Ransomware Variants Targeting Amazon S3 Services Leveraging Misconfigurations and Access Controls
ID: 8107a682-f4b4-55ef-8e9a-b75f43f4a0df
STIX ID: report--8107a682-f4b4-55ef-8e9a-b75f43f4a0df
Feed Name: cybersecurityNews.com
This report warns of a wave of ransomware campaigns targeting Amazon S3 buckets by exploiting misconfigurations and compromised credentials; researchers identified five distinct variants, including an especially destructive SSE-C variant that allows attackers to encrypt objects with attacker-held keys (preventing recovery) and leave ransom notes. It details attack techniques (encryption, deletion, exfiltration), common entry points (stolen credentials, leaked keys), and recommended mitigations such as blocking SSE-C requests, monitoring CloudTrail for anomalous activity, enforcing bucket-level protections (versioning, object lock), and maintaining secure backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
