logo

HazyBeacon Abuses AWS Lambda Function URLs for Stealthy Command-and-Control Operations

ID: f9b179f9-3a3f-58ee-ac31-1e146059302e

STIX ID: report--f9b179f9-3a3f-58ee-ac31-1e146059302e

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-07-21

Author: Divya

...
...

HazyBeacon is a stealthy cloud-native malware campaign that abuses misconfigured AWS Lambda Function URLs to establish covert command-and-control relays: attackers use stolen IAM credentials to deploy public, unauthenticated Lambda functions that proxy encrypted traffic between infected hosts and attacker infrastructure. The campaign targets government entities in Southeast Asia, leverages trusted AWS domains to evade detection, maps to ATT&CK techniques such as valid account abuse and serverless execution, and recommends identity-centric controls, comprehensive CloudTrail logging, traffic anomaly detection, and Service Control Policies to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.