What is the Attack?FortiGuard Labs Threat Team has observed recent attacks by a Threat Actor dubbed “EC2 Grouper” that leverages AWS tools for PowerShell to carry out cloud-based attacks. It leverages APIs to inventory EC2 types and available regions before executing further API calls iteratively. The Threat Actor is seen using techniques that enable remote access and lateral movement within cloud environments. EC2 Grouper is a highly active threat actor frequently involved in cloud identity compromises, observed across numerous customer environments over the years. To learn more, see the detailed Threat Blog: Catching “EC2 Grouper”- No Indicators Required! | FortiGuard LabsWhat is the recommended Mitigation?Detecting illicit use of valid cloud credentials is challenging, as most attacks lack unique indicators. By correlating weak signals, such as environmental anomalies and API usage patterns, composite alerting enhances detection accuracy significantly. For detailed guidance and Threat report, visit Fortinet’s Threat Blog | FortiGuard LabsWhat FortiGuard Coverage is available?Lacework FortiCNAPP: Cloud detection and response (CDR) addresses cloud identity compromises and uses composite alerting for enhanced detection.Lacework FortiCNAPP enhances detection efficacy and integrates CIEM to assess the impact of compromised identities.Read more about how Lacework FortiCNAPP can secure your cloud environment.
More Stories
golang-github-aws-sdk-2-20250103-1.fc42 golang-github-rclone-gofakes3-0.0.3-1.fc42 rclone-1.68.2-1.fc42
FEDORA-2025-9b0b1cc333 Packages in this update: golang-github-aws-sdk-2-20250103-1.fc42 golang-github-rclone-gofakes3-0.0.3-1.fc42 rclone-1.68.2-1.fc42 Update description: Fix for CVE-2024-52522 Read More
suricata-7.0.8-1.el8
FEDORA-EPEL-2025-02e26b51d5 Packages in this update: suricata-7.0.8-1.el8 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.fc40
FEDORA-2025-aa783e1cbd Packages in this update: suricata-7.0.8-1.fc40 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.el9
FEDORA-EPEL-2025-9dfb7c8f88 Packages in this update: suricata-7.0.8-1.el9 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.fc41
FEDORA-2025-e24171db6d Packages in this update: suricata-7.0.8-1.fc41 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
rabbitmq-server-4.0.5-2.fc42
FEDORA-2025-7c46ce9b7d Packages in this update: rabbitmq-server-4.0.5-2.fc42 Update description: Automatic update for rabbitmq-server-4.0.5-2.fc42. Changelog * Thu Jan 2 2025 Richard W.M....