HomeSecuritywhoAMI attacks allow access to AWS accounts

whoAMI attacks allow access to AWS accounts

Security experts have identified a name spoofing attack known as “whoAMI,” which allows access to Amazon Web Services (AWS) accounts to anyone who publishes an Amazon Machine Image (AMI) with a specific name.

See also: Ransomware encrypts S3 buckets via Amazon AWS

whoAMI AWS

The attack, dubbed “whoAMI,” was developed by researchers at DataDog in August 2024, demonstrating that attackers can execute code on AWS accounts. The vulnerability exploits the way software projects retrieve AMI identifiers, exposing serious security vulnerabilities.

Amazon acknowledged the vulnerability and released an update in September to address it, but the issue still exists in environments where organizations have not made the necessary code updates

Amazon Machine Images (AMIs) are pre-configured virtual machines that include the necessary software, such as operating systems and applications. They are used to create virtual servers, known as EC2 (Elastic Compute Cloud), in the AWS ecosystem, offering a flexible and efficient solution for infrastructure deployment.

AMIs are divided into public and private, each with a unique identifier. In the case of public AMIs, users can search for the appropriate identifier through the AWS catalog, making it easier to choose the AMI that meets their needs.

To ensure that the AMI comes from a trusted source in AWS Marketplace, it is important that your search includes the “owners” attribute. Without this precaution, the risk of confusion attacks related to the whoAMI name increases.

See also: EC2 Grouper abuses AWS tools for attacks

The whoAMI attack exploits incorrect AMI selection settings in AWS environments:

whoAMI attacks
  • Retrieving AMIs from software using the ec2:DescribeImages API without specifying an owner
  • Using wildcards from scripts instead of specific AMI identifiers
  • The practice of some infrastructure tools as code, such as Terraform, using “most_recent=true“, automatically selecting the most recent AMI that matches the filter.

These conditions allow malicious users to introduce misleading AMIs into the selection process, using names that resemble those of trusted resources. If no specific owner is specified, AWS returns all matching AMIs, including those created by the attacker.

The whoAMI attack does not require a compromise of the target's AWS account. The attacker simply needs their own AWS account to publish a backdoored AMI to the public Community AMI directory. They then strategically choose a name that mimics the target's AMIs, making it easy to spoof and exploit.

See also: AWS Security Incident Response: A service for responding to cyberattacks

A name confusion attack is a type of social engineering or cybersecurity exploit where an attacker manipulates or creates misleading naming schemes to impersonate trusted entities. This can involve registering domain names that closely mimic legitimate ones, such as using visually similar characters or slight spelling errors, tricking users into believing they are interacting with a trusted website or service. For example, replacing the letter “o” with a zero in a domain name can be enough to mislead users. These attacks often aim to steal sensitive information, such as login credentials or financial data, and highlight the importance of being vigilant when interacting with unknown or slightly modified entities online.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS