Threats · 104 days ago
A trusted cloud domain can be the disguise for command traffic when attackers control the account behind it. Network blocks and domain reputation checks miss that break because the relay lives inside legitimate AWS infrastructure, not on obvious attacker-owned servers.
Qualys says HazyBeacon (CL-STA-1020) is abusing AWS Lambda Function URLs set to AuthType: NONE as cloud-native C2 relays in Southeast Asian government networks. The group uses stolen IAM credentials to stand up these public endpoints and make malware talk through an Amazon-hosted URL that looks like ordinary HTTPS to AWS.
The control point is identity and configuration, not the endpoint URL itself. If cloud credentials are stolen, one account can become a trusted command channel that persists until the IAM compromise and exposed serverless settings are contained.
1 source covering this story
HazyBeacon and AWS Lambda Function URL Abuse | Cloud-Native C2 Explained | Qualys
Learn how attackers use AWS Lambda Function URLs for command and control, why cloud-native C2 is difficult to detect, and how to defend against serverless infrastructure abuse.
Part of the PlainSec briefing for 2026-06-02