Tales from the cloud trenches: Unwanted visitor
ID: 7c001e86-0988-5652-9240-55a1d6bf8114
STIX ID: report--7c001e86-0988-5652-9240-55a1d6bf8114
Feed Name: Datadog Security Labs
Attackers used a compromised AWS long-term access key to obtain console access via STS federation and sign-in tokens, created a deceptively named role (SupportAWS) that allowed assumption by an external malicious account (713521355166), attached AdministratorAccess, and created an administrative IAM user (supdev) to persist. They enumerated AWS SES (GetAccount, ListEmailIdentities, GetSendQuota) and used multiple IPs/VPN to evade detection; the report includes IP addresses, attacker account ID, and created user/role names as indicators and provides detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
