Tracking cloud-fluent threat actors - Part two: Behavioral cloud IOCs
ID: e2d9c13a-730b-53eb-b27f-87adfcf415ba
STIX ID: report--e2d9c13a-730b-53eb-b27f-87adfcf415ba
Feed Name: Wiz Blog
This report explains behavioral cloud IOCs and presents a case study of “Bapak,” an opportunistic actor that abuses exposed cloud keys to import a reused SSH public key, enumerate environment permissions, and attempt to create an ECS cluster named "bapak1". It describes a honeypot-based methodology for pivoting from observed malicious IPs and grouped API call patterns to identify additional compromised identities, and provides actionable IOCs (cluster name, SSH key names, and exact publicKeyMaterial) and guidance for integrating behavioral IOCs into detection pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
