Mitiga Security Advisory: Abusing the SSM Agent as a Remote Access Trojan
ID: 86e4e660-13e5-5e64-9686-c584f00990ef
STIX ID: report--86e4e660-13e5-5e64-9686-c584f00990ef
Feed Name: Mitiga
Mitiga discloses a post-exploitation technique that abuses the AWS Systems Manager (SSM) agent as a Remote Access Trojan on Linux and Windows by hijacking the original agent, running additional agent processes, or proxying agent traffic to attacker-controlled endpoints; the advisory outlines attack scenarios, detection indicators (duplicate instance data directories, multiple amazon-ssm-agent processes, CloudTrail Session Manager activity), and mitigations including removing SSM from allow-lists and using VPC endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
