An updated version of the commodity malware called Legion has expanded functionality to compromise SSH servers and Amazon Web Services (AWS) credentials associated with DynamoDB and CloudWatch.

“This recent update shows an expansion of the scope, with new capabilities such as the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications,” said Cado Labs researcher Matt Muir in a report shared with The Hacker News.
“It is clear that the developer’s targeting of cloud services is advancing with each iteration.”
Legion, a Python-based hacking tool, was first documented last month by the cloud security firm, detailing its ability to compromise vulnerable SMTP servers and harvest credentials.
It is also known to exploit web servers running content management systems (CMS), leverage Telegram as a data exfiltration point, and send spam SMS messages to a list of dynamically generated US mobile phone numbers using stolen SMTP credentials.

A notable addition to Legion is its ability to compromise SSH servers using the Paramiko module. It also includes features for retrieving additional AWS-specific credentials related to DynamoDB, CloudWatch, and AWS Owl from Laravel web applications.
Another change is related to the inclusion of additional paths to enumerate for the existence of .env files such as /cron/.env, /lib/.env, /sitemaps/.env, /tools/.env, /uploads/.env, and /web/.env among others.
“Incorrect settings in web applications are still the primary method Legion uses to recover credentials,” Muir said.
“Therefore, it is recommended that web application developers and administrators regularly review access to resources within the applications themselves and look for alternatives to storing secrets in context files.”
Information source: thehackernews.com
