logo

Attackers Abuse AWS Cloud to Target Southeast Asian Governments

ID: c5666c3d-3f23-5c73-b702-997b8c68d158

STIX ID: report--c5666c3d-3f23-5c73-b702-997b8c68d158

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-07-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 observed a targeted campaign (CL-STA-1020) deploying a Windows backdoor named HazyBeacon against government entities in Southeast Asia; the attackers use DLL sideloading and a persistent Windows service to run the backdoor, which communicates with actor-controlled AWS Lambda URLs for C2 and downloads additional payloads, while exfiltrating stolen data through legitimate cloud services like Google Drive and Dropbox. The report highlights the abuse of trusted cloud features to evade detection, provides IoCs, and recommends enhanced monitoring of cloud resource usage and behavioral detection to identify suspicious communications with trusted services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.