Modular “AlienFox” Toolkit Used to Steal Cloud Service Credentials

A new malware toolset was discovered and analyzed by SentinelOne security experts. Dubbed “AlienFox” by the team, the toolkit can collect credentials for multiple cloud services his providers.

SentinelOne threat researcher Alex Delamotte published an advisory Thursday that said attackers used AlienFox to extract APIs from various services, including Amazon Web Services (AWS) Simple Email Service (SES) and Microsoft Office 365. It shows that you have successfully obtained the key and secret.

“AlienFox is a modular toolset primarily distributed on Telegram in the form of source code archives. Some modules are available on GitHub and can be adopted by would-be attackers,” Delamotte explained. To do.

Many of these modules are open source, so attackers can adapt and modify them to suit their needs.

For more information on open source malware, see: Security Challenges of Open Source Software

“Regular feature evolution suggests that developers are becoming more sophisticated, and recent versions have put performance considerations at the forefront,” Delamotte wrote. .

Attackers using AlienFox used this toolkit to compile a list of misconfigured hosts from multiple security scanning platforms such as LeakIX and SecurityTrails.

“They use multiple scripts in their toolset to extract sensitive information such as API keys and secrets from configuration files exposed on the victim’s web server,” reads the SentinelOne advisory.

Additionally, some of the latest variants the team observed featured new scripts that used stolen credentials to automate malicious actions.

According to Delamotte, AlienFox’s spread represents a new trend of attacking more minimal cloud services (unsuitable for cryptomining) to enable and scale subsequent campaigns.

“Opportunistic cloud attacks are no longer limited to cryptomining. AlienFox tools facilitate attacks on minimal services that lack the resources needed for mining,” added Delamotte. . “For victims, [service credentials] Compromises can lead to additional service costs, loss of customer confidence, and remediation costs. ”

SentinelOne’s findings come days after Microsoft suggested that only 1% of all cloud permissions are actively used, which could lead to serious security risks.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *