logo

Crimson Collective hackers target AWS cloud instances for data theft

ID: b5c43631-ea48-5529-aa2f-b061e24ee0a2

STIX ID: report--b5c43631-ea48-5529-aa2f-b061e24ee0a2

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-08

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Crimson Collective has been actively compromising AWS environments by discovering exposed long-term access keys, creating privileged IAM accounts, escalating to AdministratorAccess, taking RDS/EBS snapshots and exporting data to S3, then using EC2 instances and SES to exfiltrate data and issue extortion demands — researchers observed reuse of IPs and a confirmed 570 GB exfiltration from Red Hat GitLab repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.