logo

Tales from the cloud trenches: Raiding for AWS vaults, buckets and secrets

ID: 6c3fbd42-1ded-5a0e-8a9b-c12920e8fa9b

STIX ID: report--6c3fbd42-1ded-5a0e-8a9b-c12920e8fa9b

Feed Name: Datadog Security Labs

Threat Score
65/100

Date Published: 2024-06-19

Date Updated: 2026-04-27

...
...

Datadog Security Labs observed an automated campaign (May 23–27, 2024) leveraging likely leaked long‑term AWS access keys to enumerate AWS Secrets Manager, S3 buckets, and S3 Glacier vaults across multiple regions using residential proxies and Cloudflare Warp; the attackers used a custom-signed AWS SigV4 user-agent (requests-auth-aws-sigv4). While enumeration and List* API calls (ListSecrets, ListBuckets, ListObjects, ListVaults) succeeded in some cases, no confirmed data exfiltration (GetSecretValue/GetObject/Get Job Output) was observed; the report provides IoCs (IPs and UA versions), suspected motivations, and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.