logo

Tales from the cloud trenches: The Attacker doth persist too much, methinks

ID: 0a4c81f2-319e-5b2f-ad97-9bf9df75c218

STIX ID: report--0a4c81f2-319e-5b2f-ad97-9bf9df75c218

Feed Name: Datadog Security Labs

Threat Score
78/100

Date Published: 2025-05-13

Date Updated: 2026-04-27

...
...

This report details a cloud security incident in which a leaked long-lived AWS access key tied to an AWS Organizations management account was exploited over ~150 minutes: attackers used multiple IPs to create Lambda functions (including an API-triggered "persistence-as-a-service" that can spawn IAM users), created privileged IAM users/roles and an Identity Center user/group while disabling organization-level service integrations, and performed console logins (notably from a Telegram-associated IP). The post includes IoCs (IP addresses, created IAM usernames/roles/groups, Lambda names and SHA256 hashes) and practical detection recommendations for identifying similar intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.