A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 environments to extract EC2 metadata, which may include Identity and Access Management (IAM) credentials from the IMDSv1 endpoint .
See also: AWS's ML-KEM secures TLS from quantum threats

Obtaining IAM credentials allows attackers to escalate privileges and gain access to S3 buckets or control other AWS services, which can lead to exposure, tampering with sensitive data, and service disruption.
The campaign was discovered by researchers at F5 Labs, who report that malicious activity peaked between March 13 and 25, 2025.Traffic and behavioral indicators strongly suggest that it was executed by a single threat actor.
SSRF issues are vulnerabilities in the web that allow attackers to “trap” a server into making HTTP requests to internal resources on their behalf, which are usually not accessible to the attacker.
In the campaign observed by F5, attackers targeted websites hosted on EC2 with SSRF vulnerabilities, allowing them to make remote queries to internal EC2 Metadata URLs and obtain sensitive data.
EC2 Metadata is a service in Amazon EC2 (Elastic Compute Cloud) that provides information about a virtual machine running on AWS. This information can include configuration details, network settings, and possibly security credentials.
See also: Ocelot: Amazon Web Services' (AWS) quantum computing chip
This metadata service is only accessible from the virtual machine by connecting to special URLs on internal IP addresses, such as https://169.254.169.254/latest/meta-data/.

The first SSRF malicious attempt was recorded on March 13, but the campaign fully escalated between March 15 and 25, using several FBW Networks SAS IP addresses based in France and Romania.
During this period, the attackers changed six query parameter names (dest, file, redirect, target, URI, URL) and four subdirectories (e.g., /meta-data/, /user-data), demonstrating a systematic approach to extracting sensitive data from vulnerable websites.
The attacks were successful because the vulnerable instances were running IMDSv1, AWS’s older metadata service, which allows anyone with access to retrieve metadata, including stored IAM credentials. The system has been replaced by IMDSv2, which requires session tokens (authentication) to protect websites from SSRF attacks.
See also: AWS Key Hunter: The free tool for finding exposed keys
Malicious campaignsare organized actions that aim to cause harm, mislead, or extract information, often over the internet. They are usually carried out by hackers, cybercrime , or even state actors. The purpose of these campaigns is to steal data or money, monitor or spy, damage the reputation of organizations or individuals, exert political or ideological influence, and disrupt or undermine services and infrastructure.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
