Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments
ID: b2c56302-ea65-5084-8b20-71e7923e1bcb
STIX ID: report--b2c56302-ea65-5084-8b20-71e7923e1bcb
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-08-15
Date Updated: 2026-04-28
Author: Margaret Zimmermann, Sean Johnstone, William Gamazo and Nathaniel Quist
Unit 42 discovered a large-scale cloud extortion campaign that automated internet-wide scanning of exposed .env files to harvest credentials, used stolen AWS IAM keys to create privileged roles and Lambda functions to scan and exfiltrate S3 data across at least 110,000 domains (resulting in ~90,000 leaked variables and thousands of cloud/SaaS credentials), and left ransom notes in compromised buckets; the report includes detailed TTPs, IoCs (IPs, URL, SHA256), detection queries, and mitigation recommendations such as least-privilege IAM, temporary credentials, and enabling CloudTrail/S3 logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
