Pacu is an open-source AWS post-exploitation framework developed by Rhino Security Labs for authorized offensive-security testing and assessment of AWS environments. It operates through valid AWS cloud-account credentials and provides modules for enumerating cloud resources, IAM identities and permissions, AWS security services, and network architecture, including VPC connectivity. Pacu can collect AWS environment data such as infrastructure templates, instance user data, security assessment reports, and IAM credential reports. Its functionality includes identifying AWS IAM misconfigurations and permission combinations that can enable privilege escalation, including abuse of over-permissive roles and service configurations. Pacu is intended for cloud post-compromise assessment rather than a self-propagating malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.
APT5 has accessed Microsoft M365 cloud environments using stolen credentials.
During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.
APT5 has accessed Microsoft M365 cloud environments using stolen credentials.
“By default, AWS Cognito allows authenticated users to modify their own attributes (including email) using the access token via the AWS API… UpdateUserAttributes events where email attributes are being modified.”
Late 2022 ... Persisted using ... AWS key theft and IAM manipulation.
Picking a Realistic User-Agent To blend in, pick a user-agent value that matches what the target environment likely uses... a user-agent like Boto3/1.35.0 Python/3.12.0 Botocore/1.35.0 would look normal in CloudTrail logs.
GuardDuty inspects the User-Agent header in AWS API requests (recorded in CloudTrail) to detect calls made from known penetration testing distributions... override the user-agent string natively using botocore.config.Config... removing any OS-specific identifiers that GuardDuty would flag.
By default, it comes with a 1100+ word wordlist with some common/generic role names. When a role is discovered, the script will alert you.
If an attacker compromises the management account where trusted access is enabled for IAM Access Analyzer (or the attacker enables it depending on permissions)...
For long-term credentials (Those starting with AKIA), there is an extra step that must be completed first. You will need to generate temporary credentials to retrieve the sign in token. To do this, we will make use of sts:GetFederationToken. As an alternative, sts:AssumeRole can also be used.
Compare credential scopes - Each service may have different IAM permissions ... Identify permission boundaries ... Test for privilege escalation - Use tools like Pacu or enumerate-iam with captured credentials
aws iam get-account-authorization-details... May return users, roles, groups, and policies in one call... aws iam list-roles... aws iam list-users.
While a default member account can only see itself and the management account in an organization, a delegated administrator can potentially see all AWS accounts in the organization.
Below is an example of an expect script that can take a set of AWS keys and interact with Pacu ... send -- "run aws__enum_account\r" expect "*Enumerating Account:*"
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Scott Weston has added a module to Pacu to brute force this role name or a list of role names... if a management account is compromised, and the user wants to attempt to assume one to many role names on all accounts... run organizations__assume_role
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive cloud tool cited as capable of automating identification of IAM roles and users while generating logs only in the attacker's environment.
A cloud-focused offensive tool that uses valid cloud accounts to conduct operations.
Pacu is an AWS post-exploitation framework used to identify and exploit AWS misconfigurations and privilege-escalation paths after initial access is obtained.
Cloud attack framework/tool that enumerates AWS security services such as WAF and GuardDuty.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.