Ransomware Campaign Encrypting Amazon S3 Buckets using SSE-C
ID: 48a110dc-0452-568f-bfd5-638c34c93b15
STIX ID: report--48a110dc-0452-568f-bfd5-638c34c93b15
Feed Name: Arctic Wolf
Halcyon researchers describe the Codefinger ransomware campaign that abuses compromised AWS credentials to encrypt Amazon S3 objects using SSE-C with attacker-held AES-256 keys (which AWS does not retain), then schedules deletion via S3 lifecycle policies; encrypted data cannot be recovered without the attackers' keys. Recommendations include restricting SSE-C via IAM conditions, minimizing and rotating AWS keys, enabling detailed S3 logging, and following AWS incident response guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
