Threat Advisory

Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints Ahead

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

 [/subscribe_to_unlock_form]

Summary:

 [emaillocker id="1283"]

A cloud credential theft campaign primarily targeting Amazon Web Services (AWS) credentials through public-facing Jupyter Notebooks services. This attack exploited unpatched web application vulnerabilities. Continuing into June 2023, a collaboration between Permiso and SentinelLabs tracked an evolved version of the campaign aimed at exposed Docker services. The campaign employed shell scripts as a core component, along with an Executable and Linkable Format (ELF) binary written in Golang. This development demonstrated the attackers' adaptation and inclusion of new tools. The campaign's tooling has undergone multiple updates since December. Initially focusing on AWS, the campaign expanded its scope to Azure and Google Cloud Platform (GCP) credentials in later versions.

 

The attacker's tactics in these campaigns involved extensive profiling and reconnaissance. The attack scripts performed system profiling using AWS scripts and other scripts under specific conditions. Notably, the new version introduced the "get_docker" function, which identified Docker environments and performed inspections. Furthermore, the campaign incorporated a post-exploitation script named "Data.sh" for system details collection. This script showcased the attacker's adaptation to limitations in minimal systems like containers.

 

Credential exfiltration remained a key objective for the attackers. The stolen credentials were transferred via curl to an AnonDNS-hosted server using hardcoded authentication credentials. The campaigns also introduced an ELF binary to deliver and execute additional shell scripts, adding to the attack's stealth by embedding Golang binaries. The actor's meticulous approach indicated a high level of experience, showcasing a maturing skillset. This campaign highlighted the expanding threat landscape, targeting not only AWS but also Azure and GCP, prompting organizations to bolster application security and regularly patch vulnerabilities.

 

The threat landscape has witnessed the evolution of a sophisticated cloud actor targeting public-facing services. Initially targeting AWS, the campaign expanded to Azure and GCP credentials. The attacker displayed meticulous development of modular scripts, system profiling techniques, and exfiltration methods.

 

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/08/agile-approach-to-mass-cloud-credential.html

[/emaillocker]
crossmenu