Connect with us

Infosecurity

Thousands of Leaked AWS Keys Still Active — Hundreds With Full Admin Rights

Published

on

leaked AWS keys

The Numbers Behind the Leak

Over 9,300 leaked AWS keys are still live, according to new research from Truffle Security. That’s not a typo. The security firm scanned public sources between August 2022 and August 2026 and found 64,024 unique AWS key pairs scattered across 431,875 public findings — from git history to Hugging Face datasets, Docker images, package registries, and CI logs.

Of those, 10,616 pairs had complete credentials. The researchers re-verified every single one. The result? 88% still authenticate. And here’s the scary part: 768 of those are corporate keys with full admin rights.

What an Attacker Can Do With a Leaked Key

If a malicious actor gets hold of one of these keys, they’re not just snooping around. They could steal or delete critical cloud data, or quietly install cryptocurrency mining software to monetize the access. The report notes that only 9.5% of the leaked-key accounts had a budget alert set up — meaning the other 90.5% would likely never notice the extra charges until it’s too late.

Hugging Face: The Biggest Single Source

Hugging Face was the largest source of leaked keys, with 8,482 unique live keys found across 3,394 public datasets. A staggering 18% of those had root privileges. That’s not a minor oversight; that’s a backdoor into someone’s entire cloud infrastructure.

Key Age and Rotation: The Silent Problem

For live keys with known creation dates, the median age was around five years. The oldest? Over 17 years. That’s ancient in cloud security terms.

Rotation is rare, the report notes. Of the keys where the researchers could enumerate the user’s access keys, only 13.7% (398 of 2,903) had a newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up. Once a key is out there, it stays out there.

How to Protect Your AWS Environment

Truffle Security didn’t just drop the bad news and walk away. They shared practical steps to reduce the risk of leaked keys.

  • Delete root access keys. Check every account, including personal ones. One in six leaked keys had root privileges.
  • Sort IAM keys by age. Use aws iam list-access-keys and set a maximum age policy to enforce rotation.
  • Set a budget alarm. Even a $10 alert is better than nothing. It can catch crypto-mining early, before the bill spirals.
  • Treat exposed secrets as permanently compromised. 43% of the keys discovered appeared more than once across repos, datasets, and images. If it’s out there, assume it’s burned.
  • Watch for the quarantine policy. If AWS attaches AWSCompromisedKeyQuarantine to a user, that’s AWS telling you the key is public. Act on it immediately.

The Bigger Picture: Cloud Security in 2026

This isn’t just a technical footnote. It’s a reminder that cloud security is a shared responsibility. AWS provides tools like IAM, budgets, and quarantine policies, but they only work if you use them.

The researchers also emphasized that no key material was published, and every owner they could identify is being notified. That’s good practice, but it’s not enough. If you’re a developer or a sysadmin, take a hard look at your own keys today. Check for old ones, rotate them, and set up alerts. The cost of ignoring this is far higher than a few minutes of housekeeping.

For more on related threats, check out our coverage on cloud account takeover risks and IAM key rotation best practices.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Hackers turn Android car head units into proxy botnet nodes

Published

on

Android car systems malware

First documented attack on car head units

Security researchers have uncovered a new malware campaign that targets Android-based car systems, turning them into nodes of a proxy botnet. The discovery, detailed in a report by Kaspersky on Friday, marks the first documented case of malware infecting a car head unit through an attack specifically designed for this type of device.

Head units are the computers and screens built into cars that control navigation, music, Bluetooth, and other features. Previous attacks against such systems typically relied on physical access to the vehicle or vulnerabilities in the operating system.

How the infection works

The malware was found on head units made by DoFun, a Chinese automotive software and hardware provider. Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications.

Attackers abused that functionality to push a malicious app called JarService onto affected devices. The attack requires no action from the driver — no clicking a link, visiting a malicious website, or installing anything manually. JarService has no visible user interface, making it difficult for drivers to notice their devices have been compromised.

Malware’s purpose: building a proxy botnet

JarService acts as a downloader for additional malicious code. The malware can display advertisements and generate fraudulent ad clicks, but Kaspersky said its ultimate purpose appears to be expanding a botnet — networks of infected devices that criminals can remotely use for cyberattacks, fraud, and traffic routing.

One of the malware modules observed by researchers turns infected head units into reverse proxies. This allows other people’s internet traffic to be routed through the infected device, making the activity appear to originate from the car’s internet connection. That’s a powerful tool for hiding criminal activity.

Kaspersky attributes campaign to MoYu Group

Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation. BadBox has previously compromised Android smartphones, tablets, streaming devices, and other internet-connected products.

“Despite efforts by cybersecurity professionals and law enforcement to shut down the BadBox botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide,” Kaspersky researchers said.

BadBox has a history of pre-installed malware. In 2023, cybersecurity company HUMAN Security discovered more than 70,000 Android smartphones, connected TV boxes, and tablets from at least one Chinese manufacturer that had been shipped with malware linked to the operation.

BadBox’s persistence and evolution

In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers’ command-and-control infrastructure. However, the hackers quickly resurfaced with an updated version of the botnet.

The FBI also warned last year that BadBox 2.0 was targeting internet-of-things devices, including TV streaming boxes, digital projectors, digital picture frames, and aftermarket vehicle infotainment systems. The new campaign against DoFun head units fits that pattern.

Kaspersky said it notified DoFun about the distribution scheme, and the vendor subsequently reported fixing the security issues. Still, the incident highlights a growing concern: as cars become more connected, they also become more attractive targets for cybercriminals. For related context, see our coverage of Android malware trends and botnet takedown efforts.

The discovery serves as a reminder that the internet of things extends to the vehicle in your driveway. Drivers should keep their car’s software updated and be aware that even legitimate-looking components can be exploited.

Continue Reading

Infosecurity

Def Con Attendees Targeted by Persistent Phishing Campaign

Published

on

Def Con phishing campaign

Phishing After the Conference: A New Threat

Cybersecurity conferences like Def Con and Black Hat are prime hunting grounds for threat actors. A new report from Huntress reveals a persistent phishing campaign targeting attendees after the events.

Published on August 19, the blog details how a Huntress researcher was targeted on X (formerly Twitter) following this summer’s Black Hat / Def Con. The attacker posed as CoinDesk’s VP of marketing, asking for help with a fictitious conference.

The researcher spotted the scam but played along to understand the tactics. What followed was a multi-stage attack using trusted platforms to build credibility.

The Google Doc Lure: More Than a Simple Phish

The first lure was a Google Doc disguised as a planning document. But it wasn’t your typical phishing page.

“The Google Doc was more than your typical phishing lure leading to a malicious web page. If an authenticated Google user opened it, a custom Google Apps Script sidebar was presented alongside the document,” Huntress explained.

The document asked for an ‘encryption key’ supplied by the actor in DMs. When it failed, the sidebar offered two options: ClickFix-style instructions and a download. Both were designed to execute malicious code.

This is a classic ClickFix attack pattern, where victims are tricked into running commands that bypass security controls.

A Persistent Scammer: Pivoting to Dropbox and Malware

The researcher didn’t fall for it. But the actor didn’t give up. The next day, they sent a Dropbox DocSend link leading to a counterfeit installer.

The installer was versatile, delivering different payloads based on the victim’s OS:

  • macOS: The AMOS infostealer, designed to steal credentials and sensitive data.
  • Windows: An implant targeting Ledger wallets to steal cryptocurrency, plus a proxy to evade VirusTotal checks.

“Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged,” Huntress noted. By combining social media DMs with trusted services, they created a legitimate-looking workflow.

When that failed, the actor pivoted again, asking if the researcher knew anyone wanting up to $1m in funding. This was likely another pretext to steal credentials or PII.

How to Protect Yourself After a Conference

Huntress advises conference-goers to be wary of legitimate-looking messages that lead to documents or installers requiring unusual actions.

“Unexpected requests to run terminal commands, bypass Gatekeeper, install a manual update, or enter a device password are all strong indicators of an attempt to compromise,” the report concluded.

If you’ve interacted with such a message, Huntress recommends:

  • Isolate the system from the network immediately.
  • Collect forensic evidence and consider reimaging the system.
  • Assume credentials have been compromised.
  • Revoke active sessions, reset passwords, and rotate API keys.
  • Review cryptocurrency wallets if relevant.

Staying vigilant after conferences is crucial. Attackers prey on the post-event excitement and trust. Always verify unexpected requests through a separate channel.

Continue Reading

Infosecurity

Washington sanctions VPN service that helped ransomware gangs hide in plain sight

Published

on

VPN service sanctions

A crackdown with a new target

On Monday, the U.S. Treasury Department slapped sanctions on a VPN provider and its Ukrainian administrator, accusing them of giving ransomware gangs the digital cover they needed to hit American cities, hospitals, schools and businesses. The move marks a notable shift: instead of going after the attackers themselves, Washington is now squeezing the people who sell them the tools to stay invisible.

The sanctioned service, First VPN Service (1VPNS), has been a favorite on Russian-speaking cybercrime forums for years. According to the Treasury, it provided ransomware operators with ways to “hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers.”

That’s a hefty charge. And it’s part of a broader strategy that targets not just the gangs, but the entire ecosystem that supports them.

Who got hit and why

The sanctions name two individuals. The first is Dmytro Rashevskyi, a Ukrainian national who ran 1VPNS. The Treasury says Rashevskyi used fake identities to buy infrastructure from companies that might otherwise have refused to work with him — largely because internet service providers had complained about illegal activity coming from 1VPNS servers.

The second is Yegeniy Vladimirovich Silayev, a Belarusian national. Silayev isn’t affiliated with 1VPNS, but he’s accused of selling “cryptors” — software that cloaks malware as harmless files, making it far harder for antivirus tools to detect. Think of it as a digital disguise kit for malicious code.

What the sanctions actually do

For anyone in the U.S., doing business with these designees is now off the table. That’s the immediate legal effect. But sanctions carry another weight, too: a reputational hit that often scares off customers and partners. In the cybercrime world, where trust is already thin, being blacklisted by Washington can be a serious blow to revenue.

The Treasury didn’t name specific ransomware groups that used 1VPNS. It did say that many gangs bought internet infrastructure from the service, and that the VPN was marketed on dark web forums for its ability to support botnets and scammers of all stripes — all while promising total anonymity.

Not a new operation

This isn’t the first time 1VPNS has been in the crosshairs. In May, European law enforcement agencies and the FBI took the service down, saying it had long been a haven for fraudsters and ransomware operators. The service has operated since 2014, and its selling point was simple: no logs, no cooperation with law enforcement.

Rashevskyi marketed 1VPNS as low-risk precisely because “it does not keep logs of users’ identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers,” according to the Treasury.

VPNs themselves aren’t evil, of course. Millions of people use them for privacy and security. But like any powerful tool, they can be twisted for malicious ends. The question is how far governments will go to police that gray zone.

Why this approach matters

Targeting infrastructure providers is a smart play. Instead of chasing individual hackers — who often operate from countries with little extradition appetite — the U.S. and its allies are cutting off the services that make large-scale attacks possible. Disrupt one VPN provider, and you disrupt operations for dozens of gangs at once.

That’s the theory, anyway. In practice, the effects can be harder to measure. Cybercriminals are adaptable; they’ll likely move to other services or build their own. But each sanction, each takedown, raises the cost of doing business in the underground economy.

For U.S. critical infrastructure providers — the hospitals, water systems and power grids that have been hit repeatedly — the hope is that these measures will eventually make ransomware less profitable. That’s a long game, and Monday’s action is just one move on the board.

If you’re watching the broader fight against ransomware, this is a trend worth following. The U.S. has increasingly used sanctions as a tool against cybercrime, and the list of designated entities keeps growing. For more on how these operations unfold, check out our coverage of ransomware attack response and cybercrime sanctions enforcement.

Continue Reading

Trending