Skip to content
Threat Feed

Product

AWS Backup

4 briefs RSS
high advisory

Detection of Unauthorized AWS Backup Recovery Point Deletion

Unauthorized deletion of AWS Backup recovery points via the DeleteRecoveryPoint API is an anti-recovery technique used by adversaries to prevent data restoration following destructive or ransomware attacks.

AWS Backup impact cloud-security aws ransomware
1r 1t
low advisory

Detection of AWS Backup Resource Enumeration via Long-Term Access Keys

Adversaries may use compromised long-term IAM access keys (AKIA* prefix) to enumerate AWS Backup vaults, plans, and protected resources as a precursor to ransomware activities.

AWS Backup cloud aws discovery ransomware
1r 1t
high advisory

AWS Backup Recovery Point Deletion as Anti-Recovery Tactic

Adversaries are leveraging the AWS Backup `DeleteRecoveryPoint` API call by non-service principals to remove critical data backups, a high-signal anti-recovery technique observed in ransomware and data-destruction attacks that prevents victims from restoring associated data.

AWS Backup cloud aws anti-recovery ransomware data-destruction
1r 1t
high advisory

AWS Backup Vault Deleted or Vault Lock Removed

An adversary is detected performing anti-recovery actions in AWS Backup by deleting backup vaults or removing their Vault Lock configurations via the DeleteBackupVault or DeleteBackupVaultLockConfiguration API calls, serving as a strong precursor to ransomware or data destruction, preventing organizations from restoring critical data.

AWS Backup cloud-security aws anti-recovery defense-evasion impact
1r 2t