Skip to main content
AWS S3 Ransomware: SSE-C Encryption (Codefinger) operation cover
IntermediateCloudPRO

AWS S3 Ransomware: SSE-C Encryption (Codefinger)

Client deliverables and backups at a professional-services firm are silently re-encrypted overnight using a legitimate AWS storage feature. No malware runs on any host. Working through CloudTrail, piece together how stolen service-account keys were used to install a countdown clock and lock every object behind a key only the attacker holds.

40m
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identify the account used by the attacker

15

The first unauthorized API call came from an address outside the organization. Working through the CloudTrail audit, identify the IAM user identity behind that activity.

Hint available
2

Find the primary bucket targeted

15

Two S3 buckets were attacked. Identify the one that received both the re-encrypted objects and the ransom note.

Hint available
3

Confirm the first attacker egress IP

15

The initial credential-validation and lifecycle-configuration calls share one source IP. Identify that address.

Hint available
4

Locate the countdown mechanism

20

Before a single object was re-encrypted, the attacker called an API that sets a hard deadline for automatic object deletion. Identify that API call by its CloudTrail eventName.

Hint available
5

Characterize the encryption method

20

The attacker did not use malware to encrypt files. They used a native AWS feature to write objects that no one but them can read. Identify the request header that distinguishes malicious PutObject events from normal ones in this account.

Hint available
6

Map the initial access to MITRE

15

The attacker did not exploit a vulnerability or phish a human. They obtained the key material from static configuration. Identify the MITRE ATT&CK sub-technique that describes harvesting credentials stored in files.

Hint available
7

Classify the impact technique

15

Map the re-encryption action itself to its MITRE ATT&CK technique.

Hint available

7 tasks · 115 points total

Training Tools

Cloud Console

Cloud infrastructure logs

Skills You'll Build

Investigate realistic security alerts
Cloud log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Cloud concepts

Ready to investigate?

More Operations

View all
IntermediateCloudSIEM

Exposed Kubernetes API: Cryptojacking the Cluster

Three EKS worker nodes started pegging their CPUs overnight. The Kubernetes API server was reachable from the internet with anonymous access enabled, and an automated attacker used it to deploy a privileged DaemonSet on every node, escape the container to the host, drop a Monero miner, and steal the node IAM credentials. Work the cluster audit log, host records, perimeter egress, and CloudTrail to reconstruct the full intrusion chain.

55m50 pts
IntermediateXDRSIEM

DarkGate via Microsoft Teams: External Message Lure

An IT helpdesk coordinator at a logistics firm receives an urgent Teams chat from an external IT support account. The message links to a VBS script disguised as a VPN update. Running it kicks off a silent MSI install that drops a renamed AutoIt3 loader, which decrypts DarkGate in memory, registers a scheduled task for persistence, and begins beaconing to an HTTPS C2 server. Trace the chain from the Teams lure through the loader to the active backdoor.

50m50 pts
IntermediateXDRSIEM

AsyncRAT: Malvertising to Trojanized Installer

An IT admin searching for a remote management tool clicks a paid search advertisement and downloads what appears to be a legitimate installer. The ZIP contains an AutoIt-compiled fake setup executable that drops a PowerShell loader, which fetches AsyncRAT from a staging server. The RAT establishes persistence via a scheduled task and beacons to a C2 server. Correlate web proxy records, Windows event logs, XDR file and process artifacts, and firewall egress traffic to trace the full chain from malvertising lure to active command-and-control.

45m50 pts