From social engineering to Lambda modification (Incident)
ID: 3cc206e8-1787-5b24-9bad-847cf719c49e
STIX ID: report--3cc206e8-1787-5b24-9bad-847cf719c49e
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-03
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers reported a sophisticated identity-based attack initiated through social engineering on LinkedIn and WhatsApp that resulted in credential and session-token theft; attackers used stolen cloud access keys to authenticate to Microsoft 365 and AWS, bypass MFA, modify an AWS Lambda to execute commands on EC2 instances, and conduct on-premises to cloud lateral movement while leveraging legitimate permissions to blend in with normal operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
