logo

Ransomware Campaign Encrypting Amazon S3 Buckets using SSE-C

ID: 237dfa02-47de-57ea-8b70-e422aad2107e

STIX ID: report--237dfa02-47de-57ea-8b70-e422aad2107e

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2025-01-14

Date Updated: 2026-04-27

...
...

Halcyon reports that the Codefinger group is running a ransomware campaign targeting Amazon S3 by supplying their own AES-256 keys via SSE-C during S3 PUT operations; because AWS does not retain customer-provided keys (only an HMAC is logged), data encrypted this way is unrecoverable without the attacker’s key. The campaign relies on compromised or exposed AWS credentials (with s3:GetObject and s3:PutObject permissions), and actors may also schedule object deletions via lifecycle policies; AWS and Halcyon recommend restricting SSE-C via IAM conditions, rotating and limiting keys, and enabling detailed S3 logging to detect bulk encryption or lifecycle changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.