Attackers Abuse AWS Cloud to Target Southeast Asian Governments
ID: c5666c3d-3f23-5c73-b702-997b8c68d158
STIX ID: report--c5666c3d-3f23-5c73-b702-997b8c68d158
Feed Name: Dark Reading
Date Published: 2025-07-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 observed a targeted campaign (CL-STA-1020) deploying a Windows backdoor named HazyBeacon against government entities in Southeast Asia; the attackers use DLL sideloading and a persistent Windows service to run the backdoor, which communicates with actor-controlled AWS Lambda URLs for C2 and downloads additional payloads, while exfiltrating stolen data through legitimate cloud services like Google Drive and Dropbox. The report highlights the abuse of trusted cloud features to evade detection, provides IoCs, and recommends enhanced monitoring of cloud resource usage and behavioral detection to identify suspicious communications with trusted services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
