Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days
ID: 1ddc2372-cbb2-5b33-bc20-37d40830c803
STIX ID: report--1ddc2372-cbb2-5b33-bc20-37d40830c803
Feed Name: The Register (Security)
Threat Score
A newly observed ransomware crew called Codefinger has been encrypting AWS S3 data by abusing exposed or compromised IAM keys to apply AWS SSE-C (customer-provided keys) with attacker-generated AES-256 keys, then marking objects for deletion via S3 lifecycle policies and leaving ransom notes; this leverages AWS's native encryption mechanisms to prevent victims from decrypting data and represents a potentially serious systemic risk if the technique becomes widespread.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
