Security researchers have discovered and analyzed FBot, a new Python-based hacking tool that targets cloud services.

Specifically, FBot was discovered by SentinelLabs and targets web servers, services , and Software-as-a-Service (SaaS) platforms, such as AWS, Office365, PayPal, Sendgrid, and Twilio.
FBot allows for the collection of credentials for spamming attacks, the compromise of AWS accounts , and features that allow attacks against PayPal and SaaS accounts.
See also: Phemedrone malware exploits vulnerability in Microsoft Defender SmartScreen
SentinelLabs researcher Alex Delamotte said that FBot is different from similar tools, suggesting possible private development and a more targeted distribution approach. For example, the malware does not use the widely used Androxgh0st code. Instead, it shares similarities with the Legion cloud infostealer .
The tool's features cover AWS targeting, including an AWS API Key Generator and Mass AWS Checker, as well as targeting payment services like PayPal, with a unique feature called PayPal Validator.
Also, as we mentioned above, FBot targets SaaS platforms like Sendgrid and Twilio, introducing features like Sendgrid API Key Generator, Twilio SID, and Auth Token checker. The tool also includes functions for framework reconnaissance, scanning for Laravel environments, and extracting credentials from various files.
According to SentinelLabs, FBot samples have been observed from July 2022 to January 2024. This indicates that its spread continues to this day although we are not sure if it is to the same extent.
See also: Balada Injector Malware has infected 6,700 WordPress sites
At present, no specific distribution channel has been identified for the FBot malware. In contrast, other cloud infostealers are commonly sold on platforms such as Telegram.

How can companies protect cloud services from malware attacks?
“Organizations should implement multi-factor authentication (MFA) for AWS services with programmatic access,” Delamotte warned.
“Create alerts that notify security teams when a new AWS user account is added to the organization, as well as notifications for new identities added or important configuration changes to SaaS mail applications“.
Additionally, companies can protect their cloud services from malware attacks by implementing a consistent program security . This can include installing malware detection software , updating security systems , and keeping information secure .
See also: Atomic Stealer: New version of malware targets macOS
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Companies should also educate their staff on cloud security. This can include learning about the latest trends in malware attacks, learning how to recognize and avoid phishing , and understanding the importance of keeping passwords secure.
Finally, companies can adopt practices such as a least privilege policy, where users only have the permissions they need to perform their tasks. This reduces the likelihood of malware accessing sensitive information. Additionally, using network monitoring tools can help detect unusual activity that may indicate a malware attack.
Source: www.infosecurity-magazine.com
