logo

Tracking cloud-fluent threat actors - Part two: Behavioral cloud IOCs

ID: e2d9c13a-730b-53eb-b27f-87adfcf415ba

STIX ID: report--e2d9c13a-730b-53eb-b27f-87adfcf415ba

Feed Name: Wiz Blog

Threat Score
45/100

Date Published: 2025-01-15

Date Updated: 2026-05-01

...
...

This report explains behavioral cloud IOCs and presents a case study of “Bapak,” an opportunistic actor that abuses exposed cloud keys to import a reused SSH public key, enumerate environment permissions, and attempt to create an ECS cluster named "bapak1". It describes a honeypot-based methodology for pivoting from observed malicious IPs and grouped API call patterns to identify additional compromised identities, and provides actionable IOCs (cluster name, SSH key names, and exact publicKeyMaterial) and guidance for integrating behavioral IOCs into detection pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.