Following attackers’ (Cloud)trail in AWS: Methodology and findings in the wild
ID: 5702515c-ed0d-5ecb-aa8f-9cec785b9d7f
STIX ID: report--5702515c-ed0d-5ecb-aa8f-9cec785b9d7f
Feed Name: Datadog Security Labs
This Datadog threat-hunting report documents observed malicious behavior in AWS environments between August 6 and September 7, 2023: attackers obtaining credentials, enumerating account capabilities via CloudTrail-visible API calls, attempting to create backdoor IAM users (a supplied list of suspect usernames), creating EC2 key pairs (xg1, temp_key_pair) and a security group named Java_Ghost, and using infrastructure (including identified IP addresses) to persist and abuse accounts; the report provides CloudTrail SQL and Datadog log queries plus a table of IOCs to help defenders detect these activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
