#1 Trending Cybersecurity News & Magazine
Sunday, September 17, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cyber Essentials

New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

The attackers have found a way to re-purpose the SSM agent as a Remote Access Trojan (RAT), granting them ongoing access to the compromised endpoints

Chandu Gopalakrishnan by Chandu Gopalakrishnan
August 2, 2023 - Updated on August 7, 2023
in Cyber Essentials, Firewall Daily, Vulnerabilities
0
aws agent hijack
611
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

Cybersecurity researchers at Mitiga revealed a new and sophisticated cyber threat that exploits the Amazon Web Services (AWS) Systems Manager (SSM) agent to gain control over Linux and Windows machines.

The research team, during their ongoing investigation into cloud and Software as a Service (SaaS) attacks and forensics, found this method of abusing the SSM agent – a legitimate tool used by administrators to manage their instances.

You might also like

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

The Three Trends to Watch in the Growing Threat Landscape

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

The attackers have found a way to re-purpose the SSM agent as a Remote Access Trojan (RAT), granting them ongoing access to the compromised endpoints.

AWS agent hijack: Deceptively simple

According to the Mitiga advisory, The concept behind this attack is pretty straightforward: once attackers achieve high privilege access on an endpoint with an SSM agent installed, they can manipulate the agent to perform malicious activities covertly.

“Once attackers gain their initial entry into a machine, they take the following step by uploading and installing trojans or backdoors,” Or Aspir, Head of Research at Mitiga, told The Cyber Express.

According to Or, these tools serve two key purposes.

First, they help the attackers retain ongoing access to the compromised endpoint, ensuring persistence. Second, they provide a more versatile means of controlling the endpoint while masking their activities.

What sets this attack apart is that the SSM agent binary is signed by Amazon, initially rendering it trusted and approved software by Antivirus (AV) and Endpoint Detection & Response (EDR) solutions.

As a result, the execution of the SSM agent as a RAT often goes unnoticed, evading immediate alarms and alerts, which makes detection challenging for organizations.

The researchers identified several key benefits that attackers gain by exploiting the SSM agent in this manner:

1. AWS Agent Hijack for AV and EDR Evasion: The legitimacy of the SSM agent binary allows attackers to operate without triggering immediate alarms from security solutions.

2. AWS Agent Hijack Eliminates the Need for New RAT Binaries: Attackers do not need to upload and execute new Remote Access Trojan (RAT) binaries, preventing potential detection by AV and EDR products.

3. AWS Agent Hijack Enables Legitimate Command and Control (C&C) Communication: Attackers can leverage their malicious AWS account as a Command and Control server, making their communication appear legitimate and challenging to detect.

4. No Need for Custom Code: The attackers solely rely on the SSM service and agent, eliminating the need for complex attack infrastructure development.

5. Broad Control over Endpoints: The SSM agent’s supported features like “RunCommand” or “StartSession” grant attackers effortless control over compromised endpoints.

6. Larger Attack Surface: The widespread installation and active use of the SSM agent in default Amazon Machine Images (AMIs) within the AWS ecosystem expand the potential target pool for adversaries.

AWS agent hijack: The two scenarios

According to the Mitiga advisory, there are two attack scenarios where the SSM agent could be exploited:

Scenario 1 – Hijacking the SSM agent:
In this attack, the adversaries hijack the original SSM agent process, registering it to work in “hybrid” mode with a different AWS account.

This maneuver allows them to communicate with the compromised endpoint from their own AWS account. Linux and Windows machines with an active SSM agent are susceptible to this type of attack. However, it requires the attacker to run as root on Linux or as administrator on Windows.

Scenario 2 – Running another SSM agent process:
In this scenario, attackers run an additional SSM agent process, separate from the original one, which communicates with the attacker’s AWS account.

The original SSM agent continues to operate as usual. This technique is achievable on both Linux and Windows platforms but requires the attacker to have at least non-root privileges on Linux or administrator privileges on Windows.

The threat actor must be able to run as at least non-root (but still highly) privileged user on the targeted Linux machine, or as administrator on the targeted Windows system,” said Aspir told The Cyber Express.

“The organization always needs to think about the least privilege approach in their environment and endpoint, so if something gets compromised, the attack will be still limited.”

The researchers also disclosed the potential detection methods for each attack scenario to help organizations identify suspicious activities and respond promptly.

AWS agent hijack: How to mitigate the threat

Exacerbating the situation, that attackers could bypass AWS’s servers by routing SSM traffic to attacker-controlled servers, using a proxy feature of the SSM agent, the researchers found.

This allows attackers to use the legitimate binary without AWS visibility, making it challenging to trace the attack back to the source.

AWS software and systems “are behaving as designed” and there is no need for customers to take any action, an AWS spokesperson told The Cyber Express.

The issues described in the Mitiga report require an actor to both obtain root level credentials and successfully access an EC2 instance in order to be leveraged, the spokesperson pointed out.

“As a security best practice, we recommend AWS customers follow our documentation on properly configuring VPC Endpoints with AWS Systems Manager and to use global condition keys for VPC Endpoints and VPC Endpoint Policies to mitigate the risk of inappropriate access to EC2 instances,” the spokesperson said.

Mitiga team got in touch with Amazon Web Services. Acknowledging the issue, AWS suggested a few mitigation steps.

By utilizing a Virtual Private Cloud (VPC) endpoint, you can ensure that only authorized users or services within your AWS account or organization can send commands to your EC2 instances.

Even if your instances are in a private subnet without direct internet access, the Systems Manager service can still be configured securely through the VPC endpoint.

This way, you establish a restriction that limits communication to your EC2 instances from trusted sources within your own AWS account or organization, enhancing overall cloud infrastructure security.

To implement this restriction effectively, you can set up a VPC Endpoint policy to define who has access to communicate with your EC2 instances through Systems Manager.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Previous Post

VALIC Retirement Services Company Becomes Latest MOVEit Victim

Next Post

Russian Hacker Group ‘Midnight Blizzard’ Behind Microsoft Teams Cyber Attack

Chandu Gopalakrishnan

Chandu Gopalakrishnan

Executive Editor, The Cyber Express

Related Posts

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

by Vishwa Pandagle
September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

by Editorial
September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

by Ashish Khaitan
September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

by Vishwa Pandagle
September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

by Editorial
September 16, 2023
Next Post
Microsoft Teams Cyber Attack

Russian Hacker Group 'Midnight Blizzard' Behind Microsoft Teams Cyber Attack

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

US Cybersecurity Regulations: Tracing the Past and Predicting the Future
Firewall Daily

US Cybersecurity Regulations: Tracing the Past and Predicting the Future

September 17, 2023
threat landscape
Cyber Essentials

The Three Trends to Watch in the Growing Threat Landscape

September 17, 2023
Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

September 16, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
    • World CyberCon India
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance