Computer Security News

EC2 Grouper Hackers Abusing AWS Tools to Attack With Compromised Credentials

A sophisticated hacker group dubbed “EC2 Grouper” has been exploiting AWS tools and compromised credentials to launch attacks on cloud environments.

This prolific threat actor has been observed in dozens of customer environments over the past couple of years, making them one of the most active groups tracked by cybersecurity experts.

Fortinet researchers observed that EC2 Grouper is characterized by its consistent use of AWS tools, particularly PowerShell, for executing attacks. The group employs a distinctive user agent string and a unique security group naming convention, often creating multiple groups with names like “ec2group,” “ec2group1,” up to “ec2group12345”.

The attackers primarily obtain credentials from code repositories associated with valid accounts. Once they acquire these credentials, they leverage APIs for reconnaissance, security group creation, and resource provisioning.

Their tactics include making calls to DescribeInstanceTypes to inventory EC2 types and DescribeRegions to gather information about available regions.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Interestingly, researchers have not observed calls to AuthorizeSecurityGroupIngress, which is typically required for configuring inbound access to EC2 instances launched with the security group.

However, they have noted instances of CreateInternetGateway and CreateVpc calls, which are necessary for remote access.

While the group’s ultimate objectives remain unconfirmed, experts believe resource hijacking is likely their primary goal.

No manual activity or actions based on specific objectives have been observed in compromised cloud environments, reads the report.

Detecting EC2 Grouper’s activities poses significant challenges for security teams. Traditional indicators like user agents and group names have proven unreliable for comprehensive threat detection due to their transient nature.

Instead, experts recommend a more nuanced approach that correlates multiple weak signals to identify malicious behavior accurately.

Organizations are advised to implement several security measures to mitigate risks associated with EC2 Grouper and similar threats.

These include utilizing Cloud Security Posture Management (CSPM) tools to monitor and assess cloud environment security continuously, implementing anomaly detection techniques to identify unusual behavior, and applying the principle of least privilege to all roles assigned to users and instances.

As cloud environments remain prime targets for sophisticated threat actors, the discovery and analysis of groups like EC2 Grouper underscore the importance of advanced detection mechanisms and robust security practices in safeguarding digital assets and sensitive information.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago