logo

HazyBeacon Malware Abuses AWS Lambda URLs for Stealthy C2 Communications

ID: 1fc0af81-2914-5212-bcfe-3039d4b85c1e

STIX ID: report--1fc0af81-2914-5212-bcfe-3039d4b85c1e

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Lucas Martin

...
...

Qualys has documented the HazyBeacon cloud-native malware campaign that weaponizes misconfigured AWS Lambda Function URLs (AuthType=NONE) to create covert, encrypted C2 proxies. Attackers gain access via stolen IAM credentials (e.g., from exposed repos or phishing), deploy Lambda functions with public Function URLs, and relay malicious traffic through trusted AWS domains to evade detection. The campaign targets government entities in Southeast Asia and emphasizes identity and configuration failures rather than exploitation of AWS vulnerabilities; recommended mitigations include enforcing MFA, rotating access keys, comprehensive CloudTrail logging, VPC flow log monitoring, and Service Control Policies to block public Function URL creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.