logo

Tracking cloud-fluent threat actors - Part one: Atomic cloud IOCs

ID: 8bb4482f-9ad4-59d0-a9db-1fe7919e31c3

STIX ID: report--8bb4482f-9ad4-59d0-a9db-1fe7919e31c3

Feed Name: Wiz Blog

Date Published: 2024-09-23

Date Updated: 2026-05-01

...
...

This report explains how to identify and operationalize cloud-specific atomic IOCs—such as container/VM image metadata, cloud subscription IDs, IaC artifacts, IAM user/credential naming patterns, user-agent strings, and IP addresses—to detect and investigate cloud attacks. It highlights real-world examples (e.g., TeamTNT images, DangerDev AWS accounts 671050157472 and 265857590823, AndroxGh0st-created IAM users, and IP 134.209.127.249) and maps techniques to MITRE ATT&CK. The article concludes with practical guidance for integrating these IOCs into cloud inventories and log-based detections, and references a public GitHub repository aggregating known atomic cloud IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.