logo

Incident report: From CLI to console, chasing an attacker in AWS

ID: 6fdcb693-0342-5585-a0e8-4d13f942dd86

STIX ID: report--6fdcb693-0342-5585-a0e8-4d13f942dd86

Feed Name: Expel Blog

Threat Score
60/100

Date Published: 2022-04-05

Date Updated: 2026-04-27

Author: Britton Manahan; David Blanton; Kyle Pellett; Brian Bahtiarian

...
...

An attacker used an exposed long-term AWS access key to access an environment via the CLI, discovered an IAM user, changed that user's console password to log into the AWS console, created two new IAM users with long-term access keys and administrator privileges, and requested an EC2 quota increase likely intended to support cryptocurrency mining; the activity was detected via CloudTrail-based detections and contained before major impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.