From stolen cloud key to persistence-as-a-service (Incident)
ID: 98ec8486-67ad-59d6-82e5-1a8187684be4
STIX ID: report--98ec8486-67ad-59d6-82e5-1a8187684be4
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-05-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A leaked long-term AWS access key was abused by attackers who performed SES enumeration, created admin IAM users and temporary STS credentials, and deployed a Lambda + API Gateway "persistence-as-a-service" to dynamically generate new IAM users; they also modified AWS Identity Center to bypass MFA and disabled organization-level service integrations to hinder monitoring and maintain long-term persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
