AWS Data Exfiltration and Attempted Ransomware (Campaign)
ID: f00d46a6-0a6f-50d7-b9bf-d70cd8ad6bc4
STIX ID: report--f00d46a6-0a6f-50d7-b9bf-d70cd8ad6bc4
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2025-07-08
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
In February 2025 a UK-based AWS environment was breached via compromised VPN credentials; the intruder used Nmap for internal reconnaissance, attempted lateral movement over RDP, staged sensitive finance and investment files and exfiltrated them with Rclone to external VPS endpoints, and made outbound SSH connections to known malicious IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
