Ransomware operators are increasingly integrating native Amazon Web Services (AWS) features, such as S3 buckets, compute snapshots, and cloud backup systems, into their attack toolkits to maximize the impact of their campaigns. Recent research highlights that these groups are not only targeting misconfigured cloud storage but are also leveraging built-in AWS capabilities—like encryption management and key rotation—to delete, overwrite, or render data unrecoverable, often bypassing traditional security controls. The attackers exploit customer-provided keys and other advanced cloud-native mechanisms to assert control over cryptographic protections, making recovery efforts significantly more difficult for victims.
Trend Micro researchers have identified at least five distinct ransomware variants that exploit AWS S3 misconfigurations for irreversible data destruction. Security experts note that while S3-focused attacks have been observed for years, the current trend marks a shift toward systematic abuse of cloud-native features for extortion. This evolution in tactics underscores the need for organizations to strengthen cloud security postures, particularly around key management, backup strategies, and monitoring for suspicious use of native cloud services.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Multiple reports describe the emergence of ransomware variants designed to abuse native AWS capabilities and misconfigured S3 environments, enabling attackers to encrypt or destroy cloud-stored data. The coverage highlights five cloud-native variants and a shift from traditional endpoint-focused ransomware toward direct cloud resource targeting.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcescworld.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.