{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aws-iam-roles-anywhere/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS IAM Roles Anywhere"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","persistence","iam"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAWS IAM Roles Anywhere enables workloads outside of AWS to assume IAM roles by presenting X.509 certificates validated against a registered Trust Anchor. While designed to simplify hybrid cloud identity, it introduces a persistence vector if misconfigured. Attackers with sufficient permissions can register a rogue external Certificate Authority (CA) as a Trust Anchor by configuring \u003ccode\u003esourceType\u003c/code\u003e as \u003ccode\u003eCERTIFICATE_BUNDLE\u003c/code\u003e or \u003ccode\u003eSELF_SIGNED_REPOSITORY\u003c/code\u003e instead of the AWS-managed \u003ccode\u003eAWS_ACM_PCA\u003c/code\u003e. Once established, the adversary can generate arbitrary client certificates signed by this rogue CA. These certificates allow the attacker to programmatically authenticate as sensitive IAM roles from any location, effectively bypassing AWS-native certificate lifecycle management and maintaining long-term access that survives credential rotation and standard revocation processes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for long-term, stealthy persistence within an AWS account. Attackers can assume highly privileged roles to exfiltrate data, modify cloud infrastructure, or escalate privileges further. Because the authentication is tied to a rogue CA controlled by the adversary, standard AWS-based revocation of temporary credentials or rotating service account keys will not invalidate the underlying access path until the Trust Anchor itself is deleted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the creation of any IAM Roles Anywhere Trust Anchor that does not utilize the AWS ACM Private CA.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003erolesanywhere:CreateTrustAnchor\u003c/code\u003e IAM permission to a strictly limited set of security administrators.\u003c/li\u003e\n\u003cli\u003eAudit existing Trust Anchors to ensure all registered CAs belong to approved, organizationally managed PKI infrastructure.\u003c/li\u003e\n\u003cli\u003eUtilize AWS Config or Security Hub to monitor and alert on new Trust Anchor creations and changes in their configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:40:21Z","date_published":"2026-09-18T19:40:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-iam-roles-anywhere-external-ca/","summary":"Adversaries can establish persistent access to AWS environments by creating an IAM Roles Anywhere Trust Anchor using an unauthorized external Certificate Authority (CA) to sign forged client certificates.","title":"Abuse of AWS IAM Roles Anywhere via External Trust Anchors","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-iam-roles-anywhere-external-ca/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS IAM Roles Anywhere","version":"https://jsonfeed.org/version/1.1"}