Attackers who obtain AWS programmatic credentials with broad Amazon S3 permissions can overwrite objects using server-side encryption with customer-provided keys (SSE-C). The attackers control the AES-256 keys, which AWS does not store or recover; consequently, organizations cannot decrypt the replaced objects without the original attacker-held keys. The technique can be paired with a ransom note and a seven-day bucket lifecycle deletion policy, creating both an extortion mechanism and a risk of permanent data loss.
Organizations should collect Amazon S3 data events in AWS CloudTrail and alert on successful PutObject activity specifying SSE-C/AES256 encryption, especially where the behavior is new for an IAM principal or bucket. Defenses include enabling S3 versioning to preserve recoverable object versions, enforcing least-privilege IAM and restrictive bucket policies, and monitoring changes to lifecycle configurations. S3 default server-side encryption should be configured as appropriate, but it does not eliminate the risk from authorized requests that explicitly supply attacker-controlled SSE-C keys.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs published detection-engineering research emulating SSE-C ransom activity, including compromised AWS credentials being used to overwrite S3 objects, apply a seven-day deletion lifecycle policy, and leave a ransom note. It recommended comprehensive CloudTrail S3 data-event logging and detection of anomalous SSE-C PutObject activity.
Halcyon Research Team documented what it described as the first publicly known in-the-wild ransomware use of Amazon S3 Server-Side Encryption with Customer-Provided Keys (SSE-C), in which attacker-controlled keys can deny victims access to encrypted objects.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
docs.aws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceelastic.co
Open sourcehalcyon.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.