UNC2903 is a cloud-focused intrusion actor tracked for exploiting public-facing web applications in Amazon Web Services environments to obtain and abuse temporary cloud credentials via the Amazon Instance Metadata Service. Activity observed since mid-2021 shows a multi-phase intrusion pattern that includes internet-facing infrastructure scanning, reconnaissance of exposed applications, repeated exploit attempts, and manual testing prior to credential theft and follow-on access within victim cloud tenants. The actor has been associated with exploitation of server-side request forgery conditions, including exploitation related to CVE-2021-21311 in Adminer, to query IMDSv1 and retrieve temporary AWS credentials. After obtaining credentials, UNC2903 attempted access to Amazon S3 buckets and other AWS resources and used stolen credentials for data theft and exfiltration from compromised tenants. The actor’s tradecraft centers on abusing cloud abstraction layers rather than relying solely on traditional endpoint compromise, and specifically targets environments where vulnerable third-party web applications are exposed and legacy metadata-service configurations remain enabled. Observed operations indicate hands-on-keyboard activity following initial exploitation, including manual validation and further exploration of accessible cloud resources. UNC2903 is notable for targeting exploitable applications running in AWS environments that permit metadata-service access through IMDSv1. The activity reflects a broader cloud intrusion model in which web application exploitation is used to pivot into credential access and post-exploitation within the victim’s cloud estate. No high-confidence attribution to a specific country or state sponsor is established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.