logo

Uncovering Hybrid Cloud Attacks Part 3 – The Response

ID: 479ff2af-dd45-5cad-9358-cd600823919e

STIX ID: report--479ff2af-dd45-5cad-9358-cd600823919e

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2024-09-04

Date Updated: 2026-05-01

...
...

### Executive summary This case study describes a sophisticated hybrid attack in which attackers gained and repeatedly reused a privileged AWS IAM account to retrieve instance passwords, install reverse shells on EC2 and a corporate jump server, and exfiltrate sensitive data from RDS and S3; investigators resolved the incident by combining forensic analysis, SIEM/VPC flow logs, and public threat intelligence to identify C2 infrastructure and the initial phishing compromise of an employee home PC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.