More on Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
ID: d93cf3f5-924d-5c9a-8b69-568093c7cc31
STIX ID: report--d93cf3f5-924d-5c9a-8b69-568093c7cc31
Feed Name: Mitiga
This report demonstrates that the AWS Systems Manager (SSM) agent—widely preinstalled on many AMIs—can be repurposed by an attacker as a stealthy Remote Access Trojan (RAT). It describes two primary abuse scenarios (hijacking agent registration to an attacker AWS account and running a parallel/malicious agent process via namespaces or container mode), a mock-server proxy approach to avoid AWS visibility, detection indicators (multiple instance data directories, multiple amazon-ssm-agent processes, CloudTrail Session Manager events), and defensive recommendations including removing SSM from AV/EDR allow-lists, integrating detections into SIEM/SOAR, and restricting Systems Manager access via VPC Endpoints and endpoint policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
