logo

Extortion Campaign Exploiting Exposed Environment Variable (Campaign)

ID: 4724d231-0cdc-5c67-9277-3233979b214e

STIX ID: report--4724d231-0cdc-5c67-9277-3233979b214e

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2024-08-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers uncovered a large-scale extortion campaign that scanned for exposed `.env` files to harvest sensitive credentials, gained access to misconfigured AWS environments (using API calls such as `GetCallerIdentity` and `ListUsers`), escalated privileges by creating admin IAM roles, deployed AWS Lambda functions to automate scanning and S3 data exfiltration, and left ransom notes in compromised storage — targeting over 230 million domains and harvesting ~90,000 environment variables (7,000 linked to cloud services).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.