logo

Ransomware abuses Amazon AWS feature to encrypt S3 buckets

ID: 9fcbe18d-062b-5ca0-84d9-bb1d004fb6c0

STIX ID: report--9fcbe18d-062b-5ca0-84d9-bb1d004fb6c0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-13

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A new ransomware campaign called "Codefinger" has been reported to use compromised AWS credentials to encrypt Amazon S3 objects via SSE-C (customer-provided AES-256 keys), then set object lifecycle deletion and drop ransom notes demanding Bitcoin payments; because AWS does not store SSE-C keys, victims cannot recover encrypted data without the attackers' key. Halcyon reported at least two victims and recommends preventing SSE-C usage, rotating and minimizing AWS keys and permissions, while AWS reiterates best practices for credential management and notification procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.