Incident report: From CLI to console, chasing an attacker in AWS
ID: 6fdcb693-0342-5585-a0e8-4d13f942dd86
STIX ID: report--6fdcb693-0342-5585-a0e8-4d13f942dd86
Feed Name: Expel Blog
Date Published: 2022-04-05
Date Updated: 2026-04-27
Author: Britton Manahan; David Blanton; Kyle Pellett; Brian Bahtiarian
An attacker used an exposed long-term AWS access key to access an environment via the CLI, discovered an IAM user, changed that user's console password to log into the AWS console, created two new IAM users with long-term access keys and administrator privileges, and requested an EC2 quota increase likely intended to support cryptocurrency mining; the activity was detected via CloudTrail-based detections and contained before major impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
