From NASA to Netflix, Amazon Web Services (AWS) and APIs are used by millions of small companies, enterprises, and government companies worldwide for their infrastructure needs which had gotten its eyes on the attackers now! Yes, CloudSEK’s BeVigil, a security search engine for mobile apps, has found that 0.5% of mobile apps expose AWS API keys putting their internal networks and data at high risk. It is seen that 40+ apps, with over 100 million downloads, have hardcoded private AWS keys.
The API acts like a password for the mobile apps to access data stored on AWS, for practical understanding, let’s think that AWS is your apartment that has critical data, then the API key unlocks your front door. These keys could be easily discovered by malicious hackers or competitors who could use to compromise their data and networks.
CloudSEK’s BeVigil is the world’s first security search engine for mobile apps, in April 2021. Sadly, developers are skipping this security check and they are shipped to app stores. over 10,000 apps have been uploaded to BeVigil for analysis on which 40+ apps had hardcoded private AWS keys.
| Organisation | App ID | No. of Installs | Category | Country |
| Clubfactory | club.fromfactory | 100,000,000+ | Ecommerce | India |
| Adobe Photoshopfix | com.adobe.adobephotoshopfix | 10000000 | Photography | United States |
| Adobe Comp | com.adobe.comp | 500,000+ | Art & Design | United States |
| Weather Forecast & Snow Radar | com.weather.weather | 100000000 | Weather | United States |
| Wholee – Online Shopping Store | com.wholee | 1000000 | Shopping | Singapore |
| Oven Story Pizza | in.ovenstory | 1000000 | Food & Drink | India |
| Hootsuite: | com.hootsuite.droid.full | 5000000 | Social | Canada |
AWS keys hardcoded in a mobile app source code can cause adverse effects as the attack can be chained and even attackers can get access to the codebase and config even.
This is an app in playstore with more than half a million downloads that have hardcoded AWS key and secret in its strings(.)xml file.
This key has access to multiple AWS services including ACM (Certificate Manager), ElasticBeanstalk, Kinesis, OpsWorks, S3. Collectively these 88 buckets contain 10,073,444 files and the data being exposed sums up to a total of 5.5 Terabytes.
Also, these source code, backup files, user reports, test artifacts, user uploads, logs, WordPress backup, user certificates, config files, credential files are found distributed across these buckets.
If you happen to expose your AWS key, then quickly Revoke/Delete an access key.
Also Read
WeSteal: A Cryptocurrency-Stealing Malware that Sold in Dark Web Markets
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…