The attacks leverage legitimate AWS functionality to create SNS topics, subscribe external email addresses, and publish sensitive data through API calls that appear as normal AWS service usage. Elastic Security Labs provided hunting queries that identify anomalous SNS activity by monitoring for rare user identities creating topics or subscribing with email protocols. This pub/sub messaging service, designed to enable application-to-person and application-to-application communications, is increasingly being exploited by attackers seeking to bypass traditional security controls and network monitoring. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Analysts at Elastic Security Labs identified that adversaries with access to EC2 instances can exploit attached IAM roles that have SNS permissions to establish exfiltration channels. Their research demonstrated how attackers can use native AWS CLI commands to create topics and subscribe external email addresses that receive the stolen data. Security teams are advised to implement strict IAM policies following the principle of least privilege and enable comprehensive logging of SNS activities to mitigate this emerging threat vector. This technique effectively bypasses security groups, network ACLs, and other traditional network-based protections because all communication occurs within trusted AWS infrastructure. Amazon Web Services Simple Notification Service (AWS SNS) has emerged as a new vector for malicious actors to exfiltrate sensitive data and conduct phishing campaigns. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. Organizations with permissive IAM policies or monitoring gaps may not detect this activity until after sensitive data has been compromised.
This Cyber News was published on cybersecuritynews.com. Publication date: Sat, 15 Mar 2025 14:50:17 +0000