[ad_1]
May 22, 2023Ravie LakshmananCryptocurrency / Cloud Security
A financially motivated Indonesian threat actor has been observed using Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances to perform illicit cryptocurrency mining.
Cloud security firm Permiso P0 Labs, which first detected the group in November 2021, gave it the nickname GUI-vil (pronounced Goo-ee-vil).
“The group shows a preference for graphical user interface (GUI) tools, especially the S3 browser (version 9.5.5) for their initial operations,” the company said in a report shared with The Hacker News. “After gaining access to the AWS console, they perform their operations directly through the web browser.”
Chains of attack mounted by GUI-vil involve gaining initial access by weaponizing AWS keys in publicly exposed source code repositories on GitHub or searching for GitLab instances vulnerable to remote code execution flaws (for example, CVE-2021-22205).
A successful entry is followed by elevation of privilege and internal discovery to examine all available S3 buckets and determine which services are accessible through the AWS web console.
A notable aspect of the threat actor’s modus operandi is their attempt to blend in and persist into the victim’s environment by creating new users who conform to the same naming convention and ultimately achieve their goals.
“GUI-vil will also create access keys for new identities they create so they can continue to use the S3 browser with these new users,” the company explained.
UPCOMING WEBINAR
Zero Trust + Deception: learn how to thwart attackers!
Find out how Deception can detect advanced threats, stop lateral moves, and improve your Zero Trust strategy. Join our insightful webinar!
Save my spot!
Alternatively, the group has also been spotted creating login profiles for existing users who don’t have one to allow access to the AWS console without raising any red flags.
GUI-vil’s links to Indonesia stem from the fact that the source IP addresses associated with the activities are linked to two Autonomous System Numbers (ASNs) located in the Southeast Asian country.
“The group’s main, financially motivated mission is to create EC2 instances to facilitate their crypto-mining activities,” the researchers said. “In many cases, the profits they make from crypto mining are only a fraction of the expenses victimized organizations have to pay to run EC2 instances.”
Did you find this article interesting ? Follow us on Twitter and LinkedIn to read more exclusive content we post.
|
Sources 2/ https://thehackernews.com/2023/05/indonesian-cybercriminals-exploit-aws.html The mention sources can contact us to remove/changing this article |
[ad_2]