logo

New Ransomware Variants Targeting Amazon S3 Services Leveraging Misconfigurations and Access Controls

ID: 8107a682-f4b4-55ef-8e9a-b75f43f4a0df

STIX ID: report--8107a682-f4b4-55ef-8e9a-b75f43f4a0df

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

This report warns of a wave of ransomware campaigns targeting Amazon S3 buckets by exploiting misconfigurations and compromised credentials; researchers identified five distinct variants, including an especially destructive SSE-C variant that allows attackers to encrypt objects with attacker-held keys (preventing recovery) and leave ransom notes. It details attack techniques (encryption, deletion, exfiltration), common entry points (stolen credentials, leaked keys), and recommended mitigations such as blocking SSE-C requests, monitoring CloudTrail for anomalous activity, enforcing bucket-level protections (versioning, object lock), and maintaining secure backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.