Bapak Exploiting Stolen Cloud Access Keys (Campaign)
ID: 2b9e704d-4469-57fe-938c-06349ad06e81
STIX ID: report--2b9e704d-4469-57fe-938c-06349ad06e81
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-01-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Wiz Threat Research observed an active campaign abusing leaked or stolen AWS access keys to access victims' cloud accounts, validate API keys, create ECS clusters (notably named 'bapak1' or 'entot1'), and attempt to establish persistent access by creating users and importing SSH keys; the cluster deployments are likely for crypto-mining or network scanning and the cluster names suggest a possible Indonesian origin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
