{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aws-elastic-kubernetes-service-eks/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS Elastic Kubernetes Service (EKS)","AWS IAM","AWS STS","AWS CloudTrail"],"_cs_severities":["high"],"_cs_tags":["cloud","aws","lateral-movement","credential-access","discovery"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eThis threat involves the exploitation of Kubernetes service account (SA) identities within Amazon EKS environments. Attackers leverage the EKS IAM Roles for Service Accounts (IRSA) feature, where a projected Kubernetes token is exchanged for short-lived AWS IAM credentials via the 'AssumeRoleWithWebIdentity' API. Once an adversary gains control of a pod or a compromised service account token, they use the resulting IAM session to move laterally from the containerized environment to the AWS control plane.\u003c/p\u003e\n\u003cp\u003eObserved activity includes automated reconnaissance, unauthorized access to secret management stores (AWS Secrets Manager/Parameter Store), and modifications to IAM configurations or compute instances. Defenders should focus on identifying sessions where the initial web identity token exchange is immediately followed by a high volume of non-routine administrative API calls, distinguishing this from standard pod traffic. The scope of this threat encompasses any AWS workload utilizing IRSA that is susceptible to unauthorized token use off-cluster or within the pod.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access: Adversary gains execution capability within a Kubernetes pod, often via exploit of a web application or misconfigured service.\u003c/li\u003e\n\u003cli\u003eCredential acquisition: Adversary locates the projected Kubernetes service account token, typically mounted at \u003ccode\u003e/var/run/secrets/eks.amazonaws.com/serviceaccount/token\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToken exchange: Adversary uses the service account token to call the 'AssumeRoleWithWebIdentity' API, obtaining short-lived AWS IAM session credentials.\u003c/li\u003e\n\u003cli\u003eReconnaissance: Adversary uses the obtained IAM session to call discovery APIs such as 'ListRoles', 'ListUsers', or 'ListBuckets' to map the AWS environment.\u003c/li\u003e\n\u003cli\u003eCredential access: Adversary accesses sensitive configuration data, including 'GetSecretValue' from AWS Secrets Manager or 'GetParameters' from Parameter Store.\u003c/li\u003e\n\u003cli\u003ePersistence: Adversary utilizes the session to perform IAM modifications, such as 'CreateAccessKey' or 'AttachRolePolicy', to ensure continued access.\u003c/li\u003e\n\u003cli\u003eImpact: Adversary achieves final objectives, such as data exfiltration from S3 buckets, code manipulation in Lambda, or full environment compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass Kubernetes-level security controls and gain significant privileges within the AWS account. This can result in the compromise of sensitive credentials, unauthorized modification of infrastructure, and potential exfiltration of proprietary data or intellectual property. The threat specifically impacts organizations running EKS with IRSA where service accounts are over-privileged or lack sufficient monitoring of control-plane activity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImplement the detection logic described in the provided ES-QL rule to correlate 'AssumeRoleWithWebIdentity' events with subsequent high-impact administrative API calls.\u003c/li\u003e\n\u003cli\u003eReview AWS CloudTrail logs for unexpected usage of IRSA-issued session keys originating from IP addresses or ASNs outside of the EKS cluster's VPC or NAT gateways.\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege for IAM roles associated with service accounts; audit and restrict the policies attached to these roles to the absolute minimum required permissions.\u003c/li\u003e\n\u003cli\u003eStrengthen OIDC trust conditions by utilizing 'sub' and 'aud' claims to restrict role assumption to specific, verified Kubernetes namespaces and service accounts.\u003c/li\u003e\n\u003cli\u003eConduct periodic audits of EKS audit logs to detect anomalous 'exec' activity or unauthorized secret access attempts within the cluster.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T19:37:37Z","date_published":"2026-09-18T19:37:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-k8s-lateral-movement/","summary":"Adversaries are exploiting Kubernetes service account tokens exchanged for AWS IAM credentials via AssumeRoleWithWebIdentity to conduct unauthorized reconnaissance, credential theft, and persistent access within AWS environments.","title":"AWS Lateral Movement via Kubernetes Service Account Identity Exploitation","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-k8s-lateral-movement/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS Elastic Kubernetes Service (EKS)","version":"https://jsonfeed.org/version/1.1"}