Extortion Campaign Exploiting Exposed Environment Variable (Campaign)
ID: 4724d231-0cdc-5c67-9277-3233979b214e
STIX ID: report--4724d231-0cdc-5c67-9277-3233979b214e
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-08-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers uncovered a large-scale extortion campaign that scanned for exposed `.env` files to harvest sensitive credentials, gained access to misconfigured AWS environments (using API calls such as `GetCallerIdentity` and `ListUsers`), escalated privileges by creating admin IAM roles, deployed AWS Lambda functions to automate scanning and S3 data exfiltration, and left ransom notes in compromised storage — targeting over 230 million domains and harvesting ~90,000 environment variables (7,000 linked to cloud services).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
