logo

HazyBeacon Campaign Abuses AWS for Stealthy C2 Communications

ID: a0cb9050-7b3e-5464-9fef-074d26d5d281

STIX ID: report--a0cb9050-7b3e-5464-9fef-074d26d5d281

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Mayura Kathir

...
...

HazyBeacon (CL-STA-1020) is a targeted cloud-native espionage campaign abusing stolen AWS IAM keys to create unauthenticated Lambda Function URLs as covert HTTPS C2 relays, masking attacker infrastructure and targeting government networks in Southeast Asia; the malware conducts system enumeration, remote commands, data exfiltration and keystroke capture, and mitigations focus on stricter IAM controls, credential rotation, global logging and continuous configuration audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.