Tag: AWS Services

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
News

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks

Researchers refer to this sophisticated malicious campaign as OneClik, which has been using proprietary Golang backdoors and Microsoft's ClickOnce software deployment tool to infect companies in the oil, gas, and energy industries. The hackers conceal the command and control (C2) infrastructure by using authentic AWS cloud services (AWS, Cloudfront, API Gateway, and Lambda). Microsoft's ClickOnce deployment technique minimises user intervention by enabling developers to construct Windows-based programmes that update themselves. Three versions of the campaign (v1a, BPI-MDM, and v1d) were examined by security experts at cybersecurity firm Trellix. They all used a.NET-based loader disguised as OneClikNet to install "a sophisticated Golanguage backdoor" known as RunnerBeacon read mor...
New AMBERSQUID Cryptojacking Operation Targets Uncommon AWS Services
News

New AMBERSQUID Cryptojacking Operation Targets Uncommon AWS Services

In order to covertly mine cryptocurrency, a revolutionary cloud-native cryptojacking operation has its sights set on specialized Amazon Web Services (AWS) products like AWS Amplify, AWS Fargate, and Amazon SageMaker. The cloud and container security company Sysdig has given the hostile cyber behavior the codename AMBERSQUID. "The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances," Sysdig security researcher Alessandro Brucato wrote in a study posted with The Hacker News. Targeting numerous services also presents additional difficulties, such as incident response, as it necessitates locating and eliminating all miners in each service that has been ex...