Executive Summary
AWS released a comprehensive incident response guide demonstrating two critical attack scenarios affecting cloud environments in 2025. The first scenario involves a cross-account S3 data deletion attack where threat actors assumed roles from trusted accounts, performed reconnaissance through ListBuckets operations, and executed scripted deletions of financial reports, PII databases, and production backups within a 13-second window. The second scenario showcases cryptocurrency mining operations deployed through AWS CloudFormation, where attackers leveraged console credentials without MFA to create the 'CRYPTO' stack containing EC2 instances for mining operations. Both incidents highlight the sophistication of modern cloud-native attacks that exploit legitimate AWS services and cross-account trust relationships.
These attack patterns are increasingly relevant as organizations accelerate cloud adoption while struggling with proper access controls, zero trust implementation, and multi-cloud visibility. The incidents underscore the critical need for enhanced CloudTrail monitoring, cross-account access reviews, and comprehensive egress security policies.
Why This Matters Now
Cloud environments face escalating threats as attackers increasingly target cross-account relationships and abuse legitimate cloud services for malicious purposes, making advanced CloudTrail analysis and zero trust security controls essential for modern enterprise defense.
Attack Path Analysis
Attackers compromised AWS console credentials without MFA protection and cross-account role configurations to execute multi-vector campaigns involving cryptocurrency mining resource hijacking and targeted S3 data destruction. The campaigns progressed from initial credential abuse through privilege escalation via assumed roles, lateral movement across regions and accounts, command & control through CloudShell and scripted automation, systematic data exfiltration, and final impact through ransomware-style destruction and resource consumption attacks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors obtained valid AWS console credentials lacking MFA protection and exploited misconfigured cross-account trust relationships to gain initial access
MITRE ATT&CK® Techniques
Valid Accounts
Cloud Infrastructure Discovery
Transfer Data to Cloud Account
Data Destruction
Create Cloud Instance
Resource Hijacking
Cloud Groups
Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and Protection of Critical Assets
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – User Registration and Deregistration
Control ID: A.9.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
AWS CloudTrail investigations reveal cross-account unauthorized access and cryptocurrency mining operations targeting financial data, requiring enhanced MFA enforcement and egress security controls.
Health Care / Life Sciences
Multi-vector attack campaigns exploit cloud misconfigurations to access PII databases and patient records, demanding zero trust segmentation and encrypted traffic protection.
Information Technology/IT
CloudTrail security incidents demonstrate critical need for east-west traffic security, threat detection capabilities, and comprehensive multicloud visibility across hybrid environments.
Government Administration
Cross-account role assumptions and credential harvesting attacks require immediate implementation of zero trust architecture and enhanced cloud firewall protections for sensitive operations.
Sources
- Incident response guide for AWS CloudTrail investigations – Part 1https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1/Verified
- AWS CloudTrail User Guidehttps://docs.aws.amazon.com/cloudtrail/latest/userguide/Verified
- CISA Cloud Security Technical Reference Architecturehttps://www.cisa.gov/resources-tools/resources/cloud-security-technical-reference-architectureVerified
- AWS Security Best Practices in IAMhttps://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-account AWS attack by implementing workload segmentation and identity-aware access controls. The comprehensive east-west traffic enforcement and controlled egress policies would likely have reduced the attacker's ability to move laterally across regions and exfiltrate sensitive data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely have constrained the blast radius of compromised credentials by enforcing granular workload-level authentication and reducing cross-account reachability through centralized policy enforcement
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation policies would likely have limited the scope of role assumption by constraining which services and resources could be accessed from compromised accounts, reducing the effectiveness of privilege escalation attempts
Control: East-West Traffic Security
Mitigation: Comprehensive east-west traffic controls would likely have constrained inter-service communication paths and reduced the attacker's ability to pivot between AWS services and regions through enforced segmentation boundaries
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and control mechanisms would likely have detected and constrained unauthorized CloudShell usage patterns while limiting the scope of scripted automation through real-time policy enforcement and behavioral analysis
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained large-scale data transfer operations and reduced the volume of exfiltrated sensitive data through granular outbound traffic controls and data flow restrictions
While some data destruction may still occur within compromised segments, the overall business impact would likely be significantly reduced due to constrained attacker reach and limited ability to deploy resource-intensive mining operations across the infrastructure
Impact at a Glance
Affected Business Functions
- Cloud Infrastructure Operations
- Data Storage and Backup Services
- Financial Data Management
- Customer PII Processing
Estimated downtime: 3 days
Estimated loss: $75,000
Financial reports including Q4-2024 data, customer personally identifiable information (PII) database, and production database backups were accessed and deleted. Unauthorized cryptocurrency mining operations consumed significant compute resources leading to unexpected AWS billing charges.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege access controls to prevent cross-account role abuse and limit blast radius of credential compromise
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts and cryptocurrency mining pool connections
- • Enable Multicloud Visibility & Control with centralized monitoring to detect anomalous cross-region activities, suspicious automation patterns, and rapid resource deployments
- • Enforce Encrypted Traffic (HPE) controls with comprehensive traffic inspection to identify data theft operations and prevent unencrypted sensitive data exposure
- • Activate Threat Detection & Anomaly Response capabilities to establish behavioral baselines and alert on unusual console session patterns, resource creation spikes, and scripted deletion sequences



