Site icon Information Security Buzz

Compromised Identities Deliver Malware Into AWS – Shared Assessments & YouAttest Comment

Thr rise of ransomware

BACKGROUND:

New research from Ermetic  The Urgent Threat of Ransomware to S3 Buckets. Researchers detail how compromised identities could easily deliver ransomware into the system.

Here’s the overview of the research.

AWS S3 buckets are regarded as highly reliable, so have come to be used with great confidence. What most cloud security stakeholders don’t realize is that S3 buckets face a great security risk, from an unexpected source: identities. A compromised identity with a toxic combination of entitlements can easily perform ransomware on an organization’s data.

In recent research, we used the Ermetic analysis engine on a sampling of real environments to uncover toxic scenarios in which all the following factors were true:

The study revealed very high potential for ransomware in organizations’ environments. Key findings included:

These findings, which focus on “smash and grab” operations involving a single, compromised identity, reveal a grave situation. In targeted campaigns, bad actors may move laterally to compromise multiple identities and use their combined permissions, greatly improving their ability to execute ransomware.

About the Author

Exit mobile version