logo

Following attackers’ (Cloud)trail in AWS: Methodology and findings in the wild

ID: 5702515c-ed0d-5ecb-aa8f-9cec785b9d7f

STIX ID: report--5702515c-ed0d-5ecb-aa8f-9cec785b9d7f

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2023-10-11

Date Updated: 2026-04-27

...
...

This Datadog threat-hunting report documents observed malicious behavior in AWS environments between August 6 and September 7, 2023: attackers obtaining credentials, enumerating account capabilities via CloudTrail-visible API calls, attempting to create backdoor IAM users (a supplied list of suspect usernames), creating EC2 key pairs (xg1, temp_key_pair) and a security group named Java_Ghost, and using infrastructure (including identified IP addresses) to persist and abuse accounts; the report provides CloudTrail SQL and Datadog log queries plus a table of IOCs to help defenders detect these activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.