Codefinger Ransomware Campaign Targeting S3 Buckets (Campaign)
ID: 1b442e6d-925a-5f5a-8c9f-c585ad2bb165
STIX ID: report--1b442e6d-925a-5f5a-8c9f-c585ad2bb165
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-01-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers identified a ransomware campaign named Codefinger that abuses AWS Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data in S3 buckets using compromised AWS credentials. Attackers generate and retain AES-256 keys locally (AWS only keeps an HMAC), place ransom notes in affected directories, and set S3 lifecycle policies to delete files within seven days to coerce payment — the technique abuses legitimate AWS features rather than exploiting a vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
