HomeSecurityHazyBeacon malware steals government data via AWS Lambda

HazyBeacon malware steals government data via AWS Lambda

Government organizations in Southeast Asia are being targeted by a new malware campaign aimed at collecting sensitive information through a previously unknown backdoor application called HazyBeacon.

See also: Android malware Konfety uses new obfuscation tactics

HazyBeacon malware

This activity is being monitored by Unit 42 and is codenamed CL-STA-1020, where “CL” refers to “cluster” and “STA” denotes “state-sponsored motives.” Southeast Asia has become a key cyberespionage, due to its role in sensitive trade negotiations, the modernization of its military forces, and its strategic positioning in the context of the US-China geopolitical confrontation.

Targeting state actors in the region can provide valuable insights into foreign policy, infrastructure planning, and domestic regulatory changes that affect regional and global markets.

The exact initial means of access used to install the malware remains unknown at this time, although there is evidence that it uses DLL side-loading to install itself on compromised systems. Specifically, the technique involves placing a malicious version of the “mscorsvc.dll” alongside the legitimate Windows executable “mscorsvw.exe”.

Upon execution of the executable file, the DLL is activated and begins communicating with a URL controlled by the attacker, allowing it to execute arbitrary commands and download additional malicious payload. Persistence in the system is ensured through a service, which ensures that the DLL is launched even after a computer restart.

See also: Interlock ransomware group uses new RAT malware

HazyBeacon malware stands out for leveraging AWS Lambda service URLs for command-and-control (C2), demonstrating the ongoing trend of cybercriminals abusing legitimate services to remain invisible and evade detection.

HazyBeacon malware steals government data via AWS Lambda

Defenses should pay close attention to outbound traffic to infrequently used cloud endpoints, such as *.lambda-url.*.amazonaws.com, especially when the communication originates from unusual executables or system services. While AWS usage alone is not suspicious, contextual analysis —including the origin of the process, the parent-child execution chain, and endpoint behavior—can help distinguish between legitimate activity and malware using cloud-based obfuscation methods.

The malicious payloads being downloaded include a file collection module, which is responsible for searching for and collecting files with specific extensions (e.g. doc, docx, xls, xlsx, and pdf) and within a specified time frame. It also attempts to locate files related to recent tariff measures imposed by the United States.

The attacker has been found to be using other popular services such as Google Drive and Dropbox as data extraction channels, in order to disguise his activity within normal network traffic and transmit the collected information unnoticed. In the incident analyzed by Unit 42, attempts to upload files to the cloud services were successfully thwarted.

See also: Hackers insert malware into Gravity Forms WordPress plugin

In the final stage of the HazyBeacon malware attack, the perpetrators execute cleanup commands to eliminate traces of their presence, deleting all files with the collected data and any additional malicious payloads that were previously downloaded.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS