logo

Hackers Exploited Misconfigured AWS .env Files to Attack 110,000 Domains

ID: 03841921-0db0-5318-9070-1d8adf85bb34

STIX ID: report--03841921-0db0-5318-9070-1d8adf85bb34

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2024-08-21

Date Updated: 2026-04-19

Author: Kaaviya

...
...

**Executive Summary:** Attackers exploited publicly exposed .env files to harvest hard-coded AWS IAM credentials, enabling access to victim AWS environments, privilege escalation via creation of AdministratorAccess IAM roles, and deployment of Lambda functions to scan for and exfiltrate S3 data for extortion; the campaign scanned ~230 million targets across ~110,000 domains and extracted ~90,000 unique variables. Indicators include numerous flagged IPs (Tor exit nodes, VPS and VPN endpoints) and a SHA256 for a Lambda.sh script; recommended mitigations emphasize secrets management, least-privilege IAM, encryption, secure configuration practices, and comprehensive monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.