HomeSecurityHackers steal AWS credentials via SSRF flaws

Hackers steal AWS credentials via SSRF flaws

A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 environments to extract EC2 metadata, which may include Identity and Access Management (IAM) credentials from the IMDSv1 endpoint .

See also: AWS's ML-KEM secures TLS from quantum threats

AWS SSRF

Obtaining IAM credentials allows attackers to escalate privileges and gain access to S3 buckets or control other AWS services, which can lead to exposure, tampering with sensitive data, and service disruption.

The campaign was discovered by researchers at F5 Labs, who report that malicious activity peaked between March 13 and 25, 2025.Traffic and behavioral indicators strongly suggest that it was executed by a single threat actor.

SSRF issues are vulnerabilities in the web that allow attackers to “trap” a server into making HTTP requests to internal resources on their behalf, which are usually not accessible to the attacker.

In the campaign observed by F5, attackers targeted websites hosted on EC2 with SSRF vulnerabilities, allowing them to make remote queries to internal EC2 Metadata URLs and obtain sensitive data.

EC2 Metadata is a service in Amazon EC2 (Elastic Compute Cloud) that provides information about a virtual machine running on AWS. This information can include configuration details, network settings, and possibly security credentials.

See also: Ocelot: Amazon Web Services' (AWS) quantum computing chip

This metadata service is only accessible from the virtual machine by connecting to special URLs on internal IP addresses, such as https://169.254.169.254/latest/meta-data/.

Hackers steal AWS credentials via SSRF flaws
Hackers steal AWS credentials via SSRF flaws

The first SSRF malicious attempt was recorded on March 13, but the campaign fully escalated between March 15 and 25, using several FBW Networks SAS IP addresses based in France and Romania.

During this period, the attackers changed six query parameter names (dest, file, redirect, target, URI, URL) and four subdirectories (e.g., /meta-data/, /user-data), demonstrating a systematic approach to extracting sensitive data from vulnerable websites.

The attacks were successful because the vulnerable instances were running IMDSv1, AWS’s older metadata service, which allows anyone with access to retrieve metadata, including stored IAM credentials. The system has been replaced by IMDSv2, which requires session tokens (authentication) to protect websites from SSRF attacks.

See also: AWS Key Hunter: The free tool for finding exposed keys

Malicious campaignsare organized actions that aim to cause harm, mislead, or extract information, often over the internet. They are usually carried out by hackers, cybercrime , or even state actors. The purpose of these campaigns is to steal data or money, monitor or spy, damage the reputation of organizations or individuals, exert political or ideological influence, and disrupt or undermine services and infrastructure.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS