HomeinetMisconfigured Demo Environments: Cloud Backdoors for Enterprises

Misconfigured Demo Environments: Cloud Backdoors for Enterprises

Internal testing, product demos, and security training are critical cybersecurity practices, providing defense and everyday users with the tools and knowledge to prevent and respond to threats to the enterprise. However, according to new research from Pentera Labs, when left in default or misconfigured states, these “testing” environments become Cloud Backdoors for attackers — and the problem is affecting even leading security firms and Fortune 500 companies that should know better.

See also: Backdoor LOTUSLITE targets US political entities

Cloud Backdoors
Misconfigured Demo Environments: Cloud Backdoors for Enterprises

Researchers have discovered that popular public education applications such as Hackazon, Damn Vulnerable Web Application (DVWA) , and OWASP Juice Shop have often been left accessible on the public internet via Cloud Backdoors, inadvertently exposing leading vendors including Palo Alto Networks, Cloudflare , and F5. “This is not theoretical research,” wrote Noam Yaffe, senior researcher at Pentera and head of the offensive security team, in a technical blog post.

His team found “clear evidence” that these attack paths are being exploited in practice to allow the installation of crypto miners, webshells, and persistence mechanisms. The attackers are believed to be of Eastern European origin.

His team discovered 1,926 “verified, live, and vulnerable applications,” more than half of which were running on enterprise-owned infrastructure across AWS, Azure , and Google Cloud. They then discovered 109 exposed sets of credentials, many of which were accessible through a low-priority lab environment tied to overly privileged Identity Access Management (IAM) roles.

These often provided “far more access” than a ‘training’ application should, Yaffe explained, and gave attackers: Administrator-level access to cloud accounts, as well as full access to S3 buckets, GCS, and Azure Blob Storage. The ability to launch and destroy compute resources and read and write to secret managers. Permissions to interact with container registries where images are stored, shared, and deployed. Attackers maintained persistent access, moved laterally across networks, exploited cloud credentials and other sensitive information, and mined cryptocurrency from the victim’s infrastructure.

See also: Bug in Open WebUI turns 'free model' into a backdoor

Misconfigured Demo Environments: Cloud Backdoors for Enterprises
Misconfigured Demo Environments: Cloud Backdoors for Enterprises

Additionally, Pentera researchers easily discovered active secrets such as Slack keys, GitHub tokens, and Docker Hub credentials, as well as real user data and proprietary source code. Worryingly, in DVWA, 54% of the cases discovered still used the default 'admin:password' credentials, and attackers could downgrade security settings with a single click (from “impossible” to “low”), making any embedded vulnerability “easily exploitable,” Yaffe noted.

About 20% of the DVWA cases they discovered contained artifacts deployed by malicious actors, including: XMRig Crypto Miner that was actively running, sending proceeds to wallets controlled by attackers, and was configured to operate silently without user knowledge. A “complex” watchdog script that maintained persistence even after a breach was discovered.

This included self-recovery, automatic downloads, encrypted payload delivery, evidence deletion, and switches that threat actors could use to easily terminate operations. A PHP webshell that gave attackers the ability to read, write, delete, upload, and download files, execute commands and operating system scripts on remote machines, and gain access to credentials, API keys, and other secrets embedded in the source code.

All of the discoveries were responsibly disclosed to affected organizations and then mitigated before publication, Yaffe stressed. “These were not isolated incidents. They represented an organized, ongoing exploitation campaign,” he warned. To defend against the widespread threat of Cloud Backdoors, Yaffe and his team developed SigInt, a stand-alone identification framework based on the Python language.

See also: LongNosedGoblin hackers use Windows Group Policy for attacks

Misconfigured Demo Environments: Cloud Backdoors for Enterprises
Misconfigured Demo Environments: Cloud Backdoors for Enterprises

The tool, which is available on GitHub, generates fingerprint signatures directly from a live target or GitHub repository, searches for matches, and applies a trust score. It also incorporates IP information, cloud provider detection, performance data, and provides analytics to support further investigation. Beyond that, Yaffe advised businesses to “record everything” to create a complete, up-to-date picture of all cloud resources, including ‘temporary’ and ‘test deployments,’ perform regular audits to scan for exposed services, and implement the principle of least privilege access.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS