Uncovering Hybrid Cloud Attacks Part 2 – The Attack
ID: 8b689162-a3fe-57a2-8e79-3bb6c23d9ebd
STIX ID: report--8b689162-a3fe-57a2-8e79-3bb6c23d9ebd
Feed Name: Wiz Blog
Threat Score
This report outlines a sophisticated 17+ month hybrid attack in which phishing against IT/security staff led to compromise of a personal device, Citrix session hijacking, theft of privileged AWS credentials, and automated exfiltration from S3 and RDS. Attackers maintained persistence across the home device, on‑prem jump server, and cloud, repeatedly regaining access while deleting logs and modifying audit policies to remain undetected, greatly complicating incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
