logo

Hunting for signs of persistence in the cloud: an IR guide following the CircleCI incident

ID: 285ad6d3-19b6-54a6-9e1c-8aaeca927235

STIX ID: report--285ad6d3-19b6-54a6-9e1c-8aaeca927235

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2023-01-12

Date Updated: 2026-05-01

...
...

CircleCI disclosed a January 2023 security breach that exposed thousands of organizations' secrets; this report explains how attackers could leverage compromised cloud credentials to establish persistence across AWS, Azure, and GCP. It maps likely attacker TTPs (e.g., creating users/keys, updating function code, injecting startup scripts, creating service account keys), provides Athena/KQL/GCP logging queries to hunt for suspicious activity and known malicious IPs from the CircleCI incident, and lists remediation steps to remove backdoors and revoke malicious artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.