Stolen Cloud Identity Becomes Hidden C2

A trusted cloud domain can be the disguise for command traffic when attackers control the account behind it. Network blocks and domain reputation checks miss that break because the relay lives inside legitimate AWS infrastructure, not on obvious attacker-owned servers. Qualys says HazyBeacon (CL-STA-1020) is abusing AWS Lambda Function URLs set to AuthType: NONE as cloud-native C2 relays in Southeast Asian government networks. The group uses stolen IAM credentials to stand up these public endpoints and make malware talk through an Amazon-hosted URL that looks like ordinary HTTPS to AWS. The control point is identity and configuration, not the endpoint URL itself. If cloud credentials are stolen, one account can become a trusted command channel that persists until the IAM compromise and exposed serverless settings are contained.

Part of the PlainSec briefing for 2026-06-02

Sources