Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - AWS S3 Buckets Under Siege: New Ransomware Exploits SSE-C
Ransomware Attacks News & Analysis

AWS S3 Buckets Under Siege: New Ransomware Exploits SSE-C

Josh Breaker RolfeBy Josh Breaker RolfeJanuary 15, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
AWS
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Research from the Halcyon RISE Team has revealed that a ransomware actor dubbed “Codefinger” has launched a new campaign on Amazon S3 buckets, leveraging WS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data and render victims powerless to recover data without paying the ransom.

New Technique a Systemic Threat

Halcyon says this tactic “represents a significant evolution in ransomware capabilities” and that its widespread use could “pose a systemic threat to organizations using Amazon S3 for critical data storage.”

Unlike traditional ransomware that encrypts files locally or in transit, this attack integrates directly with AWS’s secure encryption infrastructure, meaning recovery is impossible without the attacker’s symmetric AES-256 key. Moreover, as AWS CloudTrail logs only the encryption key’s hash-based message authentication code (HMAC), log evidence is limited, and recovery and forensic analysis are impossible.

Understanding the Attacker’s Workflow

According to Halcyon, Codefinger attacks in four stages:

  • Identifying Vulnerable AWS Keys: Attackers use publicly available or compromised AWS keys to locate keys with permissions to execute s3:GetObject and s3:PutObject requests.
  • Encrypting Files with SSE-C: Attackers encrypt data using their own AES-256 keys. AWS encrypts the data but doesn’t store the keys. Only an HMAC is logged, making key recovery and data decryption impossible.
  • Setting Lifecycle Policies for File Deletion: Attackers add urgency to the ransomware demand by marking files for deletion within seven days using the S3 Object Lifecycle Management API.
  • Issuing Ransom Demand: Attackers deposit ransom notes in each impacted directory, providing a Bitcoin address and client ID associated with encrypted data and warning that changes to account permissions or files will end negotiations.

This workflow highlights the attacker’s advanced technical abilities.

How Organizations Can Defend Themselves

To protect themselves from this evolving threat, Halcyon recommends organizations proactively harden AWS environments by restricting SSE-C usage, monitoring and auditing AWS keys, implementing AWS logging, and engaging with AWS support to identify potential vulnerabilities and implement tailored security measures.

Amazon Web Service’s Response

AWS has acknowledged the report, emphasizing the importance of the shared responsibility model for cloud security, encouraging customers to follow security best practices, and highlighting resources for those who suspect their credentials may have been exposed.

AWS also highlighted capabilities designed to eliminate the need to store credentials in source code or configuration files, including AM Roles, Roles Anywhere, and Identity Center, and also emphasized the use of AWS Secrets Manager to securely manage and rotate non-AWS credentials.

You can read the full statement here.

Josh Breaker Rolfe

Josh is a Content writer at Bora. He graduated with a degree in Journalism in 2021 and has a background in cybersecurity PR. He's written on a wide range of topics, from AI to Zero Trust, and is particularly interested in the impacts of cybersecurity on the wider economy.

  • Josh Breaker Rolfe
    Thales Data Threat Report: AI and Cloud Complexity Fuel New Data Security Risks
  • Josh Breaker Rolfe
    50+ Organizations Breached Due to Missing MFA
  • Josh Breaker Rolfe
    What Happens after a Phishing Email Lands in Your Inbox?
  • Josh Breaker Rolfe
    Red Hat OpenShift AI Vulnerability Allows Attackers to Seize Infrastructure Control

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}