home.social

#codefinger — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #codefinger, aggregated by home.social.

  1. #Ransomware threat actors are increasingly abusing AWS's Server-Side Encryption (SSE-C) to encrypt S3 buckets without needing to drop malware. Most recently a TA known as #Codefinger is using this technique.

    🕵 Make sure you're monitoring S3 and encryption activity via CloudTrail & GuardDuty.

    halcyon.ai/blog/abusing-aws-na

    #CloudForensics #FOR509 #AWS