A new ransomware campaign encrypts Amazon S3 buckets using AWS Server-Side Encryption with Customer Provided Keys (SSE-C) known only to the threat actor, demanding a ransom to obtain the decryption key .
See also: AWS Security Incident Response: A service for responding to cyberattacks

The campaign was discovered by Halcyon, which reported that a malicious actor known as “Codefinger” had encrypted at least two victims. However, the operation could be scaled up or the tactic could soon be adopted by more hackers.
Amazon Simple Storage Service (S3) is a scalable, secure, and high-speed object storage service from Amazon Web Services (AWS) , and S3 buckets are cloud storage containers for storing files, data backups, media, logs, and more.
SSE-C is an encryption option for securing S3 data at rest, allowing customers to use their own encryption key to encrypt and decrypt their data, using the AES-256. AWS does not store the key, and customers are responsible for key generation, management, and security.
In the Codefinger ransomware attacks, threat actors used AWS credentials to locate the victim's keys with 's3:GetObject' and 's3:PutObject' privileges, which allow these accounts to encrypt objects in S3 buckets via SSE-C. The attacker then generates an encryption key locally to encrypt the target's data.
See also: Amazon AWS: €1.2 billion investment in data centers in Italy
Since AWS does not store these encryption keys, data recovery without the attacker's key is impossible, even if the victim reports unauthorized activity to Amazon.

The attacker then sets a seven-day file deletion policy using the S3 Object Lifecycle Management API and sends ransom notes to all affected directories, which instruct the victim to pay a ransom to a given Bitcoin in exchange for the custom AES-256 key. The ransom notes also warn the victim that if they attempt to change account permissions or modify files in the bucket, the attackers will unilaterally terminate the negotiations, leaving the victim with no way to recover their data.
Halcyon reported its findings to Amazon, and the cloud said they are doing their best to immediately notify customers whose keys have been exposed so they can take immediate action. Halcyon also recommends that AWS customers set restrictive policies that prevent the use of SSE-C in their S3 buckets to protect against ransomware attacks.
Amazon also encourages people to implement strict security protocols and follow these steps to quickly resolve unauthorized AWS account activity issues. When it comes to AWS keys, unused keys should be deactivated, active keys should be rotated frequently, and account permissions should be kept to the minimum required level.
See also: AWS: Introduces passkeys and makes MFA mandatory for root users
Ransomware campaigns are one of the most aggressive forms of cybercrime today. These attacks involve malicious software that locks or encrypts files and data on systems, demanding a ransom to restore them. Perpetrators often target businesses, government organizations, or even individuals, exploiting security vulnerabilities or random user errors. The techniques used to carry out such campaigns are constantly evolving, making them particularly difficult to combat. Prevention through updated software, vigilance, and educated users is key to limiting the phenomenon.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
