logo

Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C

ID: 63fb6b0b-9871-5ac6-9d7e-bb107eb1a1d0

STIX ID: report--63fb6b0b-9871-5ac6-9d7e-bb107eb1a1d0

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon RISE reports an active ransomware campaign by an actor dubbed 'Codefinger' that uses compromised AWS credentials to apply SSE-C (customer-provided AES-256 keys) to Amazon S3 objects, producing encryption that AWS cannot decrypt since only an HMAC of the key is logged; attackers then set object lifecycle policies to delete files within seven days and drop ransom notes demanding payment for the keys. Two victims have been identified, and Halcyon recommends restricting SSE-C usage, auditing and rotating keys, enabling advanced logging, and engaging AWS support to mitigate this high-impact, emerging threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.