Elastic Security Labs detailed how AWS Security Token Service (STS) AssumeRoot can be abused when an IAM principal has overly broad permissions in an AWS Organization. The API issues temporary, task-policy-scoped credentials for the root user of a member account; in the demonstrated white-box scenario, an attacker used the IAMCreateRootUserPassword task policy to create a root login profile and prepare persistent console access. Completing the takeover would also require access to the member account’s root-email inbox to reset or establish the root password. Elastic reported no publicly known in-the-wild abuse at the time of publication.
Organizations should restrict AssumeRoot permissions and approved task policies to narrowly defined administrative roles, review delegation across member accounts, and enforce MFA and root-account credential guardrails. Security teams should retain organization-wide CloudTrail visibility and alert on unusual or rare AssumeRoot calls, especially when followed by root CreateLoginProfile activity, as these events may indicate an attempt to establish root-level persistence in a member account.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs demonstrated that overly permissive IAM-user credentials could invoke AssumeRoot with the IAMCreateRootUserPassword task policy and create a root login profile. Persistent console access would additionally require access to the member account root email inbox to complete password recovery.
AWS introduced the STS AssumeRoot API operation, which provides temporary, task-policy-scoped credentials for the root user of a member account in an AWS Organization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
docs.aws.amazon.com
Open sourceelastic.co
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.