logo

Evilginx-ing into the cloud: How we detected a red team attack in AWS

ID: d751a126-46f3-5e73-bcd0-848229efcd5e

STIX ID: report--d751a126-46f3-5e73-bcd0-848229efcd5e

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2020-12-01

Date Updated: 2026-04-27

Author: Anthony Randazzo; Bruce Potter

...
...

Expel detected a red team exercise in a customer's AWS environment where attackers used a man-in-the-middle phishing kit (Evilginx) to capture Okta session tokens and obtain AWS access keys; they then used the AWS SDK and Systems Manager StartSession to access an EC2 host, deployed a Python backdoor, and located Redshift credentials. Detection relied on correlated signals from Okta and DUO logs, CloudTrail, GuardDuty, and CrowdStrike, and the report recommends restricting API access, layering adaptive MFA, and improving cloud user compromise detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.