{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/sabotage/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS KMS"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","kms","impact","sabotage"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries are targeting AWS Key Management Service (KMS) environments by invoking the 'DeleteImportedKeyMaterial' API action on customer-managed keys that rely on imported key material (Bring Your Own Key - BYOK). Unlike the standard 'ScheduleKeyDeletion' process, which enforces a mandatory waiting period of 7 to 30 days, 'DeleteImportedKeyMaterial' executes instantly. This action transitions the target key to a 'PendingImport' state, effectively ceasing all cryptographic operations. Data encrypted under these keys becomes immediately inaccessible. If the original key material is not retained by the customer, this action results in permanent data loss. This technique is observed in the context of cloud-based ransomware and sabotage operations, where attackers aim to destroy data or hold it for ransom by controlling the availability of the decryption material. Defenders must treat this action as a high-risk destructive primitive, particularly when triggered by non-service principals.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains persistence or elevates privileges within the AWS cloud environment.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates existing KMS keys to identify those with an external origin (BYOK).\u003c/li\u003e\n\u003cli\u003eAttacker evaluates the target key's permissions to ensure they possess 'kms:DeleteImportedKeyMaterial' capabilities.\u003c/li\u003e\n\u003cli\u003eAttacker identifies critical encrypted assets (S3 buckets, EBS volumes, or RDS databases) protected by the targeted KMS keys.\u003c/li\u003e\n\u003cli\u003eAttacker executes the 'DeleteImportedKeyMaterial' API call against the chosen KMS keys.\u003c/li\u003e\n\u003cli\u003eThe target key enters 'PendingImport' state, causing immediate decryption failures across dependent cloud services.\u003c/li\u003e\n\u003cli\u003eAttacker demands ransom or destroys the original key material to ensure the data remains permanently unrecoverable.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate, widespread outage of services relying on the affected KMS keys. Depending on the data stored (e.g., S3 buckets, RDS snapshots, Secrets Manager), this leads to critical business disruption. If the adversary destroys the externally hosted key material, the data becomes unrecoverable, causing irreversible financial and operational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the suggested detection rule for 'DeleteImportedKeyMaterial' using AWS CloudTrail logs.\u003c/li\u003e\n\u003cli\u003eConfigure AWS Organizations SCPs to strictly limit the principals authorized to perform 'kms:DeleteImportedKeyMaterial' and 'kms:ImportKeyMaterial'.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized use of these KMS APIs, focusing on non-service principals and unexpected network sources.\u003c/li\u003e\n\u003cli\u003eImplement robust backup and secure storage procedures for all external key material (BYOK) used within the environment.\u003c/li\u003e\n\u003cli\u003ePerform an audit of KMS key policies to ensure the principle of least privilege is applied to destructive administrative actions.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T19:35:19Z","date_published":"2026-09-18T19:35:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-kms-key-material-deletion/","summary":"Adversaries can perform immediate data destruction in AWS by invoking the DeleteImportedKeyMaterial API, rendering all data protected by external-origin (BYOK) keys inaccessible without a recovery window.","title":"Abuse of AWS KMS DeleteImportedKeyMaterial for Data Sabotage","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-kms-key-material-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Sabotage","version":"https://jsonfeed.org/version/1.1"}