logo

110K domains targeted in 'sophisticated' AWS cloud extortion campaign

ID: fc85a7af-d882-5879-bdbe-59cc4b9f5e74

STIX ID: report--fc85a7af-d882-5879-bdbe-59cc4b9f5e74

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-21

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A large extortion campaign abused publicly exposed .env files to harvest AWS credentials, escalate privileges by creating an AdministratorAccess role named "lambda-ex", and deploy Lambda functions that scanned and replaced S3-stored data with ransom notes; Cyble researchers found attackers targeting approximately 110,000 domains and recommended secret-management, least-privilege architectures, and avoiding committing .env files to version control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.