Evilginx-ing into the cloud: How we detected a red team attack in AWS
ID: d751a126-46f3-5e73-bcd0-848229efcd5e
STIX ID: report--d751a126-46f3-5e73-bcd0-848229efcd5e
Feed Name: Expel Blog
Expel detected a red team exercise in a customer's AWS environment where attackers used a man-in-the-middle phishing kit (Evilginx) to capture Okta session tokens and obtain AWS access keys; they then used the AWS SDK and Systems Manager StartSession to access an EC2 host, deployed a Python backdoor, and located Redshift credentials. Detection relied on correlated signals from Okta and DUO logs, CloudTrail, GuardDuty, and CrowdStrike, and the report recommends restricting API access, layering adaptive MFA, and improving cloud user compromise detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
