Wiz documented Console Conceal, a technique in which an attacker with stolen IAM-user credentials and permission to call AssumeRole selects an arbitrary role-session name and creates a federated AWS Management Console session. CloudTrail records subsequent console activity under a derived temporary access key rather than the access key issued in the initiating AssumeRole event, frustrating direct access-key correlation between the activity and the compromised IAM principal.
AWS organizations should require and monitor SourceIdentity on role assumptions, as it propagates an administrator-controlled, immutable identity into subsequent CloudTrail events. For historical sessions without SourceIdentity, investigators can correlate suspicious console events to role assumptions using the role name, role-session name, and session-creation timing, while reviewing CloudTrail userIdentity fields and tightening IAM permissions that permit role assumption and custom identity-broker console access.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Wiz described Console Conceal, in which an attacker with compromised IAM credentials can assume a role using a misleading session name and create a federated AWS Console session. CloudTrail logs console activity under a temporary access key that differs from the key in the initiating AssumeRole event, impeding direct attribution; SourceIdentity can preserve attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
docs.aws.amazon.com
Open sourcewiz.io
Open sourcedocs.aws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.