logo

Bapak Exploiting Stolen Cloud Access Keys (Campaign)

ID: 2b9e704d-4469-57fe-938c-06349ad06e81

STIX ID: report--2b9e704d-4469-57fe-938c-06349ad06e81

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2025-01-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Threat Research observed an active campaign abusing leaked or stolen AWS access keys to access victims' cloud accounts, validate API keys, create ECS clusters (notably named 'bapak1' or 'entot1'), and attempt to establish persistent access by creating users and importing SSH keys; the cluster deployments are likely for crypto-mining or network scanning and the cluster names suggest a possible Indonesian origin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.