{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aws-iot-secure-tunneling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:amazon:aws_iot_secure_tunneling:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS IoT Secure Tunneling"],"_cs_severities":["high"],"_cs_tags":["aws-iot","command-and-control","tunneling","post-exploitation"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries are leveraging the legitimate, signed AWS IoT Secure Tunneling \u003ccode\u003elocalproxy\u003c/code\u003e binary for post-exploitation command-and-control (C2) and persistent remote access. This technique involves executing the binary on a compromised host in 'destination' mode, which instructs the proxy to establish an outbound connection to the AWS IoT Secure Tunneling data plane (\u003ccode\u003edata.tunneling.iot.\u0026lt;region\u0026gt;.amazonaws.com\u003c/code\u003e) via port 443. Once connected, the proxy relays traffic from the attacker's workstation to local services on the victim host, such as SSH on localhost:22. Because this tool is a documented, signed AWS component often used for legitimate device management, its execution can easily blend into authorized administrative activity. Notably, the C2 channel is established using the attacker's own AWS account credentials, leaving no \u003ccode\u003eOpenTunnel\u003c/code\u003e events in the victim's CloudTrail logs, making detection dependent on endpoint-level process and network behavior monitoring.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker achieves initial access to a target host and identifies it as a candidate for persistent remote access.\u003c/li\u003e\n\u003cli\u003eAttacker drops the legitimate \u003ccode\u003elocalproxy\u003c/code\u003e binary onto the target filesystem or uses an existing copy if available.\u003c/li\u003e\n\u003cli\u003eAttacker executes \u003ccode\u003elocalproxy\u003c/code\u003e with destination-mode flags (e.g., \u003ccode\u003e-d\u003c/code\u003e, \u003ccode\u003e--destination-app\u003c/code\u003e, or \u003ccode\u003e-m dst\u003c/code\u003e) to prepare the host to receive tunnel traffic.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elocalproxy\u003c/code\u003e process initiates a DNS lookup for the AWS Secure Tunneling data plane endpoint (\u003ccode\u003edata.tunneling.iot.\u0026lt;region\u0026gt;.amazonaws.com\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe process establishes an outbound TCP/443 connection to the resolved AWS endpoint to register the destination.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a connection from their own infrastructure through the Secure Tunneling service.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elocalproxy\u003c/code\u003e receives the traffic from the tunnel and forwards it to the specified local service (e.g., TCP 127.0.0.1:22).\u003c/li\u003e\n\u003cli\u003eAttacker gains interactive access to the victim host through the established relay.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of this technique provides adversaries with a stealthy, persistent, and authorized-looking C2 channel that bypasses many traditional perimeter defenses. It enables unauthorized remote access to internal services, potential data exfiltration, and lateral movement from the compromised host, all while utilizing AWS-managed infrastructure that is often implicitly trusted by corporate security policies.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of process and network correlation rules to detect unauthorized execution of the \u003ccode\u003elocalproxy\u003c/code\u003e binary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided EQL detection rule to your SIEM and tune against known-legitimate administrative device-management activity.\u003c/li\u003e\n\u003cli\u003eMonitor for and alert on DNS queries to \u003ccode\u003e*.tunneling.iot.*.amazonaws.com\u003c/code\u003e originating from endpoints not explicitly authorized for AWS IoT device management.\u003c/li\u003e\n\u003cli\u003eIsolate hosts where \u003ccode\u003elocalproxy\u003c/code\u003e is identified without a corresponding business justification and block the C2 domain at the DNS or egress firewall level.\u003c/li\u003e\n\u003cli\u003eInvestigate any local connections from the \u003ccode\u003elocalproxy\u003c/code\u003e process to sensitive local services like SSH (22) or RDP (3389) during the process execution window.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T04:12:21Z","date_published":"2026-09-29T04:12:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-iot-tunneling-abuse/","summary":"Adversaries are abusing the legitimate AWS IoT Secure Tunneling localproxy binary in destination mode to establish unauthorized remote access tunnels through AWS-managed infrastructure.","title":"Abuse of AWS IoT Secure Tunneling Localproxy for Post-Exploitation C2","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-iot-tunneling-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS IoT Secure Tunneling","version":"https://jsonfeed.org/version/1.1"}