logo

HazyBeacon Weaponizes AWS Lambda Function URLs for Stealth Command-and-Control Relays

ID: 8bd4277d-6feb-5e89-afcd-99338229d71f

STIX ID: report--8bd4277d-6feb-5e89-afcd-99338229d71f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Abinaya

...
...

HazyBeacon (CL-STA-1020) is a stealthy cyber-espionage campaign targeting Southeast Asian government networks that weaponizes misconfigured AWS Lambda Function URLs (AuthType:NONE) as covert command-and-control relays. Attackers use stolen IAM credentials to deploy public Lambda functions that forward encrypted malware traffic through trusted on.aws domains, masking destinations and making detection difficult; the backdoor profiles systems, executes commands, and exfiltrates data. Recommended defenses include strong IAM hygiene (MFA, key rotation), enabling CloudTrail across regions, monitoring network and VPC flow logs, applying SCPs to block public Function URLs, and behavioral/cloud-visibility monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.