Defending Against Codefinger Ransomware in AWS S3 by Lucie Cardiet
ID: 045e055d-53de-5861-a89f-84686bb52334
STIX ID: report--045e055d-53de-5861-a89f-84686bb52334
Feed Name: Vectra AI Blog
This report describes the Codefinger cloud-native ransomware campaign that abuses compromised AWS API keys and S3 SSE-C to encrypt objects and mark them for deletion, preventing recovery via normal means. It breaks down the attack workflow from initial access and discovery to encryption and ransom deployment, provides preventative controls (short-term credentials, S3 versioning/object locking, restricting SSE-C, centralized key management, logging/monitoring) and detection/response best practices, and highlights how the Vectra AI platform can aid visibility, prioritization, and automated containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
