logo

HazyBeacon Campaign Exploits AWS Lambda for Stealthy Cyber Espionage

ID: cd7dca29-e77c-5006-993d-5ca5465b291f

STIX ID: report--cd7dca29-e77c-5006-993d-5ca5465b291f

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-24

...
...

HazyBeacon (CL-STA-1020) is a stealthy cyber-espionage campaign observed by Qualys that targets Southeast Asian government networks by exploiting misconfigured AWS Lambda Function URLs and stolen cloud credentials to establish covert command-and-control channels; the technique mixes malicious activity into trusted cloud infrastructure, making detection difficult. The report notes significant national-security implications but discloses no CVEs, tools, or indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.