logo

FortiGuard Labs Links New EC2 Grouper Hackers to AWS Credential Exploits

ID: 5eec1222-3ca0-5716-aa4e-f2841f10f8cd

STIX ID: report--5eec1222-3ca0-5716-aa4e-f2841f10f8cd

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-01-01

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers from FortiGuard Labs tracked an actor named EC2 Grouper that steals AWS credentials (often from code repositories) and uses API-driven activity and AWS tooling to create resources and persist in cloud environments; the group leaves weak but recurring indicators such as security group naming patterns and user agents, making detection challenging and prompting recommendations to use CSPM, secret-scanning alerts, and anomaly detection to identify credential misuse and unusual API activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.