logo

From social engineering to Lambda modification (Incident)

ID: 3cc206e8-1787-5b24-9bad-847cf719c49e

STIX ID: report--3cc206e8-1787-5b24-9bad-847cf719c49e

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-02-03

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers reported a sophisticated identity-based attack initiated through social engineering on LinkedIn and WhatsApp that resulted in credential and session-token theft; attackers used stolen cloud access keys to authenticate to Microsoft 365 and AWS, bypass MFA, modify an AWS Lambda to execute commands on EC2 instances, and conduct on-premises to cloud lateral movement while leveraging legitimate permissions to blend in with normal operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.