AWS .Env Files Hacked in Cloud Extortion Campaign, Data Held for Ransom

Published:

spot_img

Cloud Extortion Campaign Targets 100,000 Domains Using Misconfigured AWS .env Files

Researchers from Palo Alto Networks’ Unit 42 have uncovered a sophisticated extortion campaign that targeted over 100,000 domains by exploiting misconfigured AWS environment variable files (.env files) to ransom data stored in cloud containers. The attackers utilized automation techniques and in-depth knowledge of cloud architecture to enhance the speed and success of their campaign, highlighting the critical need for robust cloud security practices.

The campaign capitalized on multiple security failures within cloud users’ environments, including exposed environment variables, the use of long-lived credentials, and the absence of a least privilege architecture. By setting up infrastructure within organizations’ AWS environments, the attackers scanned over 230 million unique targets for sensitive information.

In total, the campaign targeted 110,000 domains, resulting in the exposure of more than 90,000 unique variables in .env files. The attackers successfully ransomed data hosted within cloud storage containers by exfiltrating the data and leaving ransom notes in compromised containers.

The researchers emphasized that the attack was not a result of vulnerabilities in cloud providers’ services but rather misconfigurations within victim organizations that exposed their .env files. The threat actors behind the campaign demonstrated advanced automation techniques and a deep understanding of cloud architectural processes.

Initial access to organizations’ cloud environments was gained through leaked AWS IAM credentials found in exposed .env files. The threat actors leveraged these credentials to escalate their privileges within victim cloud environments and create new AWS Lambda functions for their automated scanning operation.

The researchers noted a growing trend of attackers targeting cloud IAM credentials for initial access, emphasizing the importance of securing sensitive files and implementing strong authentication and access controls in cloud environments.

spot_img

Related articles

Recent articles

Cleopatra Hospitals Group Cuts Cyber-Incident Investigation Times by 75% with Kaspersky Solution

Cleopatra Hospitals Group (CHG), the largest private healthcare network in Egypt, has successfully reduced its investigation times for high-severity cyber incidents from eight hours...

Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration from Connected Apps

Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications...

Microsoft Identifies MacSync Stealer’s Evolving Infrastructure and Data Exfiltration Techniques

Microsoft Defender Experts have identified the MacSync Stealer, a macOS-focused information stealer that utilizes evolving infrastructure for payload delivery, communication with compromised devices, and...

Q2 2026 Report Reveals Surge in Vulnerability Disclosures and Evolving Threat Landscape

The cybersecurity landscape is undergoing significant changes, as highlighted in the latest Quarterly Threat Landscape Report from Rapid7 Labs. The report reveals a dramatic...