Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HazyBeacon Exploits AWS Lambda for Covert Cyber Operations

HazyBeacon Exploits AWS Lambda for Covert Cyber Operations

Posted on June 19, 2026 By CWS

A sophisticated cyber-espionage campaign known as HazyBeacon is targeting government entities in Southeast Asia, utilizing AWS Lambda Function URLs to execute stealthy command-and-control operations. The campaign, tracked as CL-STA-1020, exemplifies the growing trend of leveraging cloud services for malicious activities.

Innovative Use of Cloud Infrastructure

Security experts at Qualys have identified that attackers are exploiting AWS serverless functions and compromised cloud credentials to merge harmful activities within trusted AWS frameworks. This blending makes it challenging for traditional security systems to detect.

Previously, malware operations depended on attacker-owned servers, which were susceptible to blocking through IP or domain reputation. HazyBeacon, however, introduces a cloud-native approach, embedding its infrastructure within legitimate cloud services and using AWS-hosted Lambda Function URLs for communication.

Exploiting AWS Lambda Function URLs

The primary tactic involves manipulating AWS Lambda Function URLs configured with AuthType: NONE, which allows public access without authentication. These endpoints provide a straightforward HTTPS interface, bypassing the need for additional tools like API Gateway, thus reducing detection risks.

Attackers capitalize on stolen Identity and Access Management (IAM) credentials to establish Lambda functions in compromised accounts, configure public URLs, and use these for encrypted malware communications. The traffic, appearing legitimate due to the trusted AWS domain, poses a significant challenge for defenders.

Defense Strategies and Future Implications

HazyBeacon’s strategy aligns with a borrowed-infrastructure model, where adversaries use third-party cloud environments for their operations. This includes stealing IAM keys via phishing, deploying infrastructure using AWS APIs, and establishing public Function URLs for data transmission.

The malware operates as a lightweight backdoor, gathering system profiles, executing commands remotely, and extracting sensitive information. The campaign underscores the need for robust IAM practices, including key rotation and multi-factor authentication, to prevent unauthorized access.

Organizations are advised to implement comprehensive logging through AWS CloudTrail and monitor VPC flow logs to detect suspicious activities. Additionally, applying Service Control Policies (SCPs) to restrict public Lambda Function URLs and tracking unusual cost spikes can help mitigate risks.

As attackers continue to exploit cloud services for increased stealth and scalability, it is crucial for organizations to focus on identity-centric security measures, ongoing configuration assessments, and behavioral analysis of cloud operations.

Cyber Security News Tags:API Gateway, AWS Lambda, cloud infrastructure, cloud security, cyber attack, cyber defense, cyber espionage, HazyBeacon, IAM, Malware, network security, Qualys, Service Control Policies, Southeast Asia, VPC flow logs

Post navigation

Previous Post: AI’s Role in Transforming Threat Management Strategies
Next Post: eFAQ Exposes Coordinated Online Reputation Attack

Related Posts

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks Cyber Security News
Apache bRPC Vulnerability Enables Remote Command Injection Apache bRPC Vulnerability Enables Remote Command Injection Cyber Security News
CISOs Guide to Regulatory Compliance in Global Landscapes CISOs Guide to Regulatory Compliance in Global Landscapes Cyber Security News
IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Cyber Security News
Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Cyber Security News
Chinese Hackers Organization Influence U.S. Government Policy on International Issues Chinese Hackers Organization Influence U.S. Government Policy on International Issues Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Key Cybersecurity Updates: Apple, Delta, AWS Announcements
  • Global Crackdown on SocGholish Malware Cleans Thousands of Sites
  • Critical Flaws in Chrome Extensions Risk Millions
  • CISA Urges Fortinet Users to Secure Devices Amid Attack
  • eFAQ Exposes Coordinated Online Reputation Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Key Cybersecurity Updates: Apple, Delta, AWS Announcements
  • Global Crackdown on SocGholish Malware Cleans Thousands of Sites
  • Critical Flaws in Chrome Extensions Risk Millions
  • CISA Urges Fortinet Users to Secure Devices Amid Attack
  • eFAQ Exposes Coordinated Online Reputation Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark