logo

From stolen cloud key to persistence-as-a-service (Incident)

ID: 98ec8486-67ad-59d6-82e5-1a8187684be4

STIX ID: report--98ec8486-67ad-59d6-82e5-1a8187684be4

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2025-05-13

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A leaked long-term AWS access key was abused by attackers who performed SES enumeration, created admin IAM users and temporary STS credentials, and deployed a Lambda + API Gateway "persistence-as-a-service" to dynamically generate new IAM users; they also modified AWS Identity Center to bypass MFA and disabled organization-level service integrations to hinder monitoring and maintain long-term persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.