logo

Tales from the cloud trenches: Unwanted visitor

ID: 7c001e86-0988-5652-9240-55a1d6bf8114

STIX ID: report--7c001e86-0988-5652-9240-55a1d6bf8114

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2024-12-11

Date Updated: 2026-04-27

...
...

Attackers used a compromised AWS long-term access key to obtain console access via STS federation and sign-in tokens, created a deceptively named role (SupportAWS) that allowed assumption by an external malicious account (713521355166), attached AdministratorAccess, and created an administrative IAM user (supdev) to persist. They enumerated AWS SES (GetAccount, ListEmailIdentities, GetSendQuota) and used multiple IPs/VPN to evade detection; the report includes IP addresses, attacker account ID, and created user/role names as indicators and provides detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.