Skip to content
Threat Feed

Tag

Encryption

12 briefs RSS
high advisory

Unusual AWS S3 Object Encryption with SSE-C

Adversaries with compromised AWS credentials can exploit Server-Side Encryption with Customer-Provided Keys (SSE-C) in Amazon S3 to encrypt objects, rendering them unreadable and potentially enabling ransomware operations, which detection engineers can identify by monitoring CloudTrail logs for specific `PutObject` or `CopyObject` API calls.

Amazon S3 cloud aws s3 ransomware encryption impact data-loss
1r 2t
critical threat

The Gentlemen Ransomware: Self-Propagating Go Encryptor

The Gentlemen ransomware, operated by Storm-2697 as a RaaS, employs a combination of strong per-file encryption with aggressive self-propagation to achieve broad network compromise, targeting Windows environments and using double extortion tactics.

Microsoft Defender Storm-2697 ransomware raas lateral-movement encryption
2r 4t
medium advisory

WinRAR and 7-Zip Encryption Abuse for Data Exfiltration Preparation

Adversaries use WinRAR or 7-Zip to create encrypted archives in preparation for data exfiltration, using command-line arguments to enable encryption functionality.

WinRAR +1 data-exfiltration archive encryption windows
3r 2t
medium advisory

AWS KMS Key User Performing S3 Encryption

Detection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.

AWS Identity and Access Management +2 aws kms s3 cloud encryption
2r 1t
medium advisory

AWS EBS Encryption Disabled

Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region, potentially leading to data exposure and weakening data protection against exfiltration or ransomware.

Elastic Block Store aws ebs encryption cloudtrail
2r 2t
medium advisory

AWS KMS Key User Performing S3 Encryption Detection

Detection of AWS users utilizing KMS keys to perform encryption operations on S3 buckets, indicating potential misuse or malicious activity within the cloud environment.

AWS Key Management Service +3 cloud aws kms s3 encryption
2r 1t
medium advisory

PowerShell Script with Encryption/Decryption Capabilities

PowerShell scripts employing .NET cryptography APIs are used to encrypt data for impact or decrypt payloads for defense evasion.

Elastic Endpoint Security +1 powershell encryption defense-evasion windows
2r 3t
high advisory

ESXi Encryption Settings Modified

Attackers modify ESXi host encryption settings, such as disabling secure boot or executable verification, to weaken hypervisor integrity and enable unauthorized code execution.

ESXi encryption vmware defense-evasion privilege-escalation
2r 2t
high advisory

ESXi Encryption Settings Modification

Detection of modifications to ESXi host encryption settings, such as disabling secure boot or executable verification, which may indicate attempts to weaken hypervisor integrity and allow unauthorized code execution.

ESXi +3 encryption vmware hypervisor attack.persistence
2r
medium advisory

AWS User Performing S3 Encryption with KMS Keys

A user with KMS keys is performing encryption operations on S3 buckets, potentially masking exfiltration or tampering efforts by encrypting sensitive data to evade detection or preparing it for exfiltration.

S3 +1 aws encryption ransomware
2r 1t
high advisory

AWS KMS Key Creation with Public Encryption Policy

An attacker may create AWS KMS keys with a permissive encryption policy, granting `kms:Encrypt` permissions to all principals, potentially leading to unauthorized encryption and data compromise across multiple organizations.

AWS Key Management Service aws kms encryption misconfiguration ransomware
2r 1t
medium advisory

AWS IAM Key Creation with Encryption Policy but Without MFA

Detection of AWS IAM users creating access keys with encryption policies applied while failing to use multi-factor authentication, potentially indicating compromised accounts or malicious privilege escalation.

Identity and Access Management aws iam access_key encryption mfa
2r 2t