logo

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

ID: 1ddc2372-cbb2-5b33-bc20-37d40830c803

STIX ID: report--1ddc2372-cbb2-5b33-bc20-37d40830c803

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-01-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A newly observed ransomware crew called Codefinger has been encrypting AWS S3 data by abusing exposed or compromised IAM keys to apply AWS SSE-C (customer-provided keys) with attacker-generated AES-256 keys, then marking objects for deletion via S3 lifecycle policies and leaving ransom notes; this leverages AWS's native encryption mechanisms to prevent victims from decrypting data and represents a potentially serious systemic risk if the technique becomes widespread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.