Datadog Security Research identified a password-spraying campaign that made repeated failed AWS ConsoleLogin attempts against root accounts at more than 150 organizations between July 24 and August 23. Victims typically received only a few attempts—median two and as many as eight—with no observed successful authentications or confirmed account compromises. The actors used outdated Chrome/Edge 85 and Firefox 120 user-agent strings and geographically distributed proxy infrastructure spanning multiple countries and autonomous systems.
Because failed root-console authentication requires the email address associated with the AWS root user, the activity indicates the attackers likely obtained root-email addresses or successfully enumerated likely account-email candidates. Organizations should review AWS CloudTrail for root ConsoleLogin events, alert on all root-account activity, eliminate persistent root credentials where possible, and apply distinct protections to management-account root users. Mandatory AWS root-user MFA, enforced since June 2025, can prevent takeover even if a root password is compromised.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Between July 24 and August 23, attackers conducted repeated failed AWS ConsoleLogin attempts against root accounts at more than 150 organizations. Datadog observed no successful authentications or confirmed compromises.
AWS IAM began enforcing multi-factor authentication for root users across all AWS account types, with a 35-day grace period after a root user’s first console sign-in attempt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourcesecuritylabs.datadoghq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.