Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HazyBeacon Exploits AWS for Covert Cyber Operations

HazyBeacon Exploits AWS for Covert Cyber Operations

Posted on June 3, 2026 By CWS

A sophisticated malware campaign known as HazyBeacon is leveraging trusted cloud services to target government networks in Southeast Asia. The campaign, identified as CL-STA-1020, cleverly utilizes Amazon Web Services (AWS) to mask its malicious activities.

Using AWS for Stealthy Operations

HazyBeacon operates by compromising AWS accounts of unrelated entities to deploy serverless functions as covert relay points. This approach allows the malware to maintain discreet communication with infected systems. To network defenders, these interactions appear as standard HTTPS traffic directed towards AWS infrastructure, complicating detection efforts.

Qualys researchers, in collaboration with Cyber Security News, revealed that the campaign was initially highlighted by Palo Alto Networks Unit 42 in July 2025. Their report provides a detailed analysis, including strategies for detecting and mitigating this cloud-native threat.

Mechanics of HazyBeacon

Upon installation on a Windows system, HazyBeacon acts as a backdoor, gathering system data such as hostname and IP address. It receives encrypted instructions to execute shell commands or download additional payloads, effectively exfiltrating documents and keystrokes without detection.

The malware does not exploit AWS vulnerabilities but rather relies on stolen IAM access keys obtained through exposed GitHub repositories or phishing. These keys are instrumental in creating relays within compromised cloud accounts.

Exploiting AWS Lambda Functionality

The attack’s foundation lies in the misuse of AWS Lambda Function URLs, introduced in April 2022. These URLs allow serverless functions direct internet exposure, which, while beneficial for developers, presents an opportunity for exploitation. Attackers prefer the AuthType: NONE setting, enabling public HTTPS relay creation without authentication, making the traffic blend seamlessly with legitimate AWS activity.

The relay facilitates encrypted HTTP POST requests to a Lambda URL in a compromised account, forwarding payloads to the attacker’s backend server. Typically, neither the victim nor the AWS account holder realizes the breach until receiving an abuse alert or unexpected billing spike.

Defensive Measures Against AWS Exploitation

To combat such threats, robust IAM practices are crucial. Deactivating unused keys, implementing regular rotations, and enforcing multi-factor authentication can thwart initial access attempts. Additionally, enabling AWS CloudTrail logging across all regions can uncover unauthorized deployments by tracking API calls related to Lambda functions.

Organizations can also enforce Service Control Policies to prevent unauthorized public relays and route Lambda functions through Virtual Private Clouds for enhanced detection. Monitoring for unusual Lambda usage and cost spikes can further alert organizations to potential abuse.

Stay updated with the latest cyber threats and defenses by following us on Google News, LinkedIn, and X, and set CSN as your preferred source for timely information.

Cyber Security News Tags:AWS, AWS Lambda, cloud infrastructure, cloud security, cyber attacks, Cybersecurity, HazyBeacon, IAM, IAM access keys, Lambda, Malware, Phishing, security researchers, serverless functions, Southeast Asia

Post navigation

Previous Post: New Malspam Campaign Exploits Google DoubleClick
Next Post: Microsoft 365 Android Apps Vulnerability Allows Token Theft

Related Posts

Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets Cyber Security News
New NFCShare Malware Targets Android Banking Apps New NFCShare Malware Targets Android Banking Apps Cyber Security News
English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks Cyber Security News
Rockstar Data Breach: 78.6 Million Records Exposed Rockstar Data Breach: 78.6 Million Records Exposed Cyber Security News
Scattered Spider Upgraded Their Tactics to Abuse Legitimate Tools to Evade Detection and Maintain Persistence Scattered Spider Upgraded Their Tactics to Abuse Legitimate Tools to Evade Detection and Maintain Persistence Cyber Security News
NDSS Symposium 2027 Set for Seoul Launch NDSS Symposium 2027 Set for Seoul Launch Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark