Ransomware Gang Exploits AWS Native Encryption

A new ransomware group, dubbed 'Codefinger,' is targeting AWS S3 buckets and leveraging the cloud giant's own server-side encryption with customer-provided keys (SSE-C) to encrypt victims' data. They use leaked AWS keys to encrypt files with AES-256 and set a 7-day self-destruct timer. This unique approach exploits AWS's own security features, making data recovery difficult without the attacker's key. Security experts recommend restricting SSE-C usage, regularly auditing AWS keys, and implementing the principle of least privilege to mitigate risk.
Read more