
AWS S3 Ransomware: SSE-C Encryption (Codefinger)
Client deliverables and backups at a professional-services firm are silently re-encrypted overnight using a legitimate AWS storage feature. No malware runs on any host. Working through CloudTrail, piece together how stolen service-account keys were used to install a countdown clock and lock every object behind a key only the attacker holds.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Identify the account used by the attacker
15The first unauthorized API call came from an address outside the organization. Working through the CloudTrail audit, identify the IAM user identity behind that activity.
Find the primary bucket targeted
15Two S3 buckets were attacked. Identify the one that received both the re-encrypted objects and the ransom note.
Confirm the first attacker egress IP
15The initial credential-validation and lifecycle-configuration calls share one source IP. Identify that address.
Locate the countdown mechanism
20Before a single object was re-encrypted, the attacker called an API that sets a hard deadline for automatic object deletion. Identify that API call by its CloudTrail eventName.
Characterize the encryption method
20The attacker did not use malware to encrypt files. They used a native AWS feature to write objects that no one but them can read. Identify the request header that distinguishes malicious PutObject events from normal ones in this account.
Map the initial access to MITRE
15The attacker did not exploit a vulnerability or phish a human. They obtained the key material from static configuration. Identify the MITRE ATT&CK sub-technique that describes harvesting credentials stored in files.
Classify the impact technique
15Map the re-encryption action itself to its MITRE ATT&CK technique.
7 tasks · 115 points total
Training Tools
Cloud Console
Cloud infrastructure logs
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with Cloud concepts
Ready to investigate?
More Operations
View allExposed Kubernetes API: Cryptojacking the Cluster
Three EKS worker nodes started pegging their CPUs overnight. The Kubernetes API server was reachable from the internet with anonymous access enabled, and an automated attacker used it to deploy a privileged DaemonSet on every node, escape the container to the host, drop a Monero miner, and steal the node IAM credentials. Work the cluster audit log, host records, perimeter egress, and CloudTrail to reconstruct the full intrusion chain.
DarkGate via Microsoft Teams: External Message Lure
An IT helpdesk coordinator at a logistics firm receives an urgent Teams chat from an external IT support account. The message links to a VBS script disguised as a VPN update. Running it kicks off a silent MSI install that drops a renamed AutoIt3 loader, which decrypts DarkGate in memory, registers a scheduled task for persistence, and begins beaconing to an HTTPS C2 server. Trace the chain from the Teams lure through the loader to the active backdoor.
AsyncRAT: Malvertising to Trojanized Installer
An IT admin searching for a remote management tool clicks a paid search advertisement and downloads what appears to be a legitimate installer. The ZIP contains an AutoIt-compiled fake setup executable that drops a PowerShell loader, which fetches AsyncRAT from a staging server. The RAT establishes persistence via a scheduled task and beacons to a C2 server. Correlate web proxy records, Windows event logs, XDR file and process artifacts, and firewall egress traffic to trace the full chain from malvertising lure to active command-and-control.