Mandiant reported that UNC2903 targeted public-facing web applications in AWS environments to steal temporary cloud credentials by abusing the Amazon Instance Metadata Service (IMDS). The activity began in 2021 and relied on server-side request forgery (SSRF) in vulnerable applications, including Adminer affected by CVE-2021-21311, to query metadata endpoints and retrieve AWS credentials tied to the compromised instances.
After obtaining credentials, the threat actor attempted access to S3 buckets and other AWS resources in what Mandiant described as a multi-phase intrusion chain involving internet scanning, reconnaissance, exploit attempts, and manual validation before credential abuse and data theft. The report said environments still using IMDSv1 were especially exposed, while IMDSv2 and GuardDuty offer stronger defenses, and warned that similar metadata-service abuse could affect other cloud platforms with comparable features.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2024-03-25, Mandiant publicly reported UNC2903's AWS-focused metadata-service abuse, highlighting exposure from IMDSv1 and recommending mitigations such as IMDSv2 and GuardDuty.
After obtaining credentials from IMDS, UNC2903 attempted access to S3 buckets and other cloud resources as part of a multi-phase intrusion sequence that included scanning, reconnaissance, exploit attempts, manual testing, and data exfiltration.
Beginning in 2021, Mandiant observed UNC2903 targeting public-facing web applications in AWS environments and exploiting server-side request forgery flaws to query the Amazon Instance Metadata Service for temporary credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.