HazyBeacon Malware Abuses AWS Lambda URLs for Stealthy C2 Communications
ID: 1fc0af81-2914-5212-bcfe-3039d4b85c1e
STIX ID: report--1fc0af81-2914-5212-bcfe-3039d4b85c1e
Feed Name: Cyber Press
Qualys has documented the HazyBeacon cloud-native malware campaign that weaponizes misconfigured AWS Lambda Function URLs (AuthType=NONE) to create covert, encrypted C2 proxies. Attackers gain access via stolen IAM credentials (e.g., from exposed repos or phishing), deploy Lambda functions with public Function URLs, and relay malicious traffic through trusted AWS domains to evade detection. The campaign targets government entities in Southeast Asia and emphasizes identity and configuration failures rather than exploitation of AWS vulnerabilities; recommended mitigations include enforcing MFA, rotating access keys, comprehensive CloudTrail logging, VPC flow log monitoring, and Service Control Policies to block public Function URL creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
