HomeSecurityHackers exploit AWS X-Ray service

Hackers exploit AWS X-Ray service

A sophisticated technique has been uncovered where malicious actors exploit Amazon Web Services ’ (AWS) X-Ray distributed trace analysis service to create covert command and control (C2) communications. This demonstrates how legitimate cloud infrastructure can be used for malicious purposes.

See also: ShadowV2 Botnet Exploits Docker Containers on AWS

AWS X-Ray
Hackers exploit AWS X-Ray service

AWS X-Ray, designed to help developers analyze application performance through distributed traces, has been reused by Red Team researchers in a steganographic communication channel called XRayC2.

This technique exploits X-Ray's annotation system, which allows for the storage of arbitrary key-value data, to pass commands and extract data via legitimate AWS API calls to the xray.[region].amazonaws.com.

According to Dhiraj, the attack methodology exploits X-Ray's trace segment functionality, where malicious payloads are embedded in seemingly innocent tracking data. Attackers use the PutTraceSegments, GetTraceSummaries , and BatchGetTraces to create two-way communication channels that blend seamlessly with normal cloud traffic.

See also: AWSDoor: Hiding malware in the AWS Cloud Environment

Hackers exploit AWS X-Ray service
Hackers exploit AWS X-Ray service

The implant establishes its presence via beacon markers containing system information encoded in trace annotations, including service type identifiers such as “health_check” and unique instance identifiers. Command delivery is accomplished via base64-encoded payloads stored in configuration annotations, while outputting results uses execution_result within the trace data structures.

This technique demonstrates advanced evasion capabilities by implementing custom AWS Signature Version 4 (SigV4) authentication , creating legitimate AWS API traffic that is naturally integrated with standard network logs. The malicious communication uses random beacon intervals between 30 and 60 seconds and uses HMAC-SHA256 signing with access keys, following the format of a regular Amazon request.

The XRayC2 tool requires minimal AWS permissions, using the AWSXRayDaemonWriteAccess along with custom permissions for trace handling. This approach significantly reduces the attack surface compared to traditional C2 infrastructure, while maintaining persistent access through native cloud services.

See also: Hackers abuse Amazon SES for phishing attacks

Hackers exploit AWS X-Ray service
Hackers exploit AWS X-Ray service

The detection of this technique presents challenges for security teams, as the malicious activity appears as typical application performance monitoring activities. Organizations must implement enhanced monitoring of X-Ray API usage patterns, establish baseline metrics for trace annotation data volumes, and examine unusual service interactions within their AWS environments to identify potential abuse of legitimate cloud services for covert communications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS