{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/organizations/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS Organizations"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","organizations","persistence","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAWS Organizations allows the management account to designate member accounts as delegated administrators for specific AWS services. This allows the delegated account to manage the service on behalf of the organization without requiring direct access to the management account. Threat actors who compromise a principal with excessive 'organizations:RegisterDelegatedAdministrator' permissions can exploit this mechanism to elevate an attacker-controlled member account to a position of organization-wide administrative authority. This provides an effective method for persistence and lateral movement, as the attacker can subsequently use the delegated administrator's permissions to manipulate sensitive resources, modify IAM policies, or compromise other member accounts across the entire organization. Defenders must monitor CloudTrail logs for unexpected usage of the RegisterDelegatedAdministrator API to prevent unauthorized privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker compromises an IAM principal in the AWS management account that possesses overly permissive IAM policies (e.g., broad organizations:* access).\u003c/li\u003e\n\u003cli\u003eAttacker enumerates available AWS accounts within the organization to identify a candidate member account for takeover.\u003c/li\u003e\n\u003cli\u003eAttacker uses the compromised credentials to invoke the 'organizations:RegisterDelegatedAdministrator' API call.\u003c/li\u003e\n\u003cli\u003eAttacker specifies the target member account ID and the desired AWS service (e.g., Identity Center or CloudFormation StackSets) in the API request parameters.\u003c/li\u003e\n\u003cli\u003eAWS registers the attacker-controlled account as the delegated administrator for the target service, granting it organization-wide administrative scope.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates as the delegated administrator identity.\u003c/li\u003e\n\u003cli\u003eAttacker executes administrative actions (e.g., creating new IAM roles, modifying StackSets, or accessing sensitive data) across the organization.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistence and exfiltrates data or pivots further into the organization's infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over specific AWS services for the entire organization. This leads to privilege escalation, potential lateral movement to all member accounts, and the ability to modify organizational security policies, create backdoors, or exfiltrate sensitive data managed within the organization's cloud environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy detection for 'organizations:RegisterDelegatedAdministrator' in AWS CloudTrail to identify unauthorized delegation attempts.\u003c/li\u003e\n\u003cli\u003eAudit all currently registered delegated administrators using 'organizations:ListDelegatedAdministrators' to ensure they align with the organization's planned configuration.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to IAM policies, ensuring 'organizations:RegisterDelegatedAdministrator' is restricted to a dedicated, MFA-authenticated role.\u003c/li\u003e\n\u003cli\u003eReview and revoke broad 'organizations:*' permissions from non-essential management account principals.\u003c/li\u003e\n\u003cli\u003eInvestigate any successful API calls identified in the detection rule to verify if the delegated account belongs to the organization's legitimate inventory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T10:42:24Z","date_published":"2026-09-07T10:42:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-delegated-admin/","summary":"An attacker with compromised credentials possessing 'organizations:RegisterDelegatedAdministrator' permissions can escalate privileges by designating an attacker-controlled member account as a delegated administrator for sensitive services to gain organization-wide control.","title":"AWS Organizations Delegated Administrator Registration","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-delegated-admin/"}],"language":"en","title":"CraftedSignal Threat Feed - Organizations","version":"https://jsonfeed.org/version/1.1"}