Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan

Teilen:

Cybersecurity researchers have discovered a new post-exploitation technique in Amazon Web Services (AWS) that allows the AWS Systems Manager Agent (SSM Agent) to be run as a remote access trojan on Windows and Linux environments

The SSM agent, a legitimate tool used by admins to manage their instances, can be re-purposed by an attacker who has achieved high privilege access on an endpoint with SSM agent installed, to carry out malicious activities on an ongoing basis, Mitiga researchers Ariel Szarf and Or Aspir said in a report shared with The Hacker News.

This allows an attacker who has compromised a machine, hosted on AWS or anywhere else, to maintain access to it and perform various malicious activities.

SSM Agent is a software installed on Amazon Elastic Compute Cloud (Amazon EC2) instances that makes it possible for administrators to update, manage, and configure their AWS resources through a unified interface.

The advantages of using an SSM Agent as a trojan are manifold in that it is trusted by endpoint security solutions and eliminates the need for deploying additional malware that may trigger detection. To further muddy the waters, a threat actor could use their own malicious AWS account as a command-and-control (C2) to remotely supervise the compromised SSM Agent.

The post-exploitation techniques detailed by Mitiga presupposes that an attacker already has permissions to execute commands on the Linux or Windows endpoint that also has an SSM Agent installed and running.

Specifically, it entails hijacking and registering an SSM Agent to run in hybrid mode, allowing it to communicate with different AWS accounts other than the original AWS account where the EC2 instance is hosted. This causes the SSM Agent to execute commands from an attacker-owned AWS account.

An alternative approach uses the Linux namespaces feature to launch a second SSM Agent process, which communicates with the attacker’s AWS account, while the already running SSM agent continues to communicate with the original AWS account.

Last but not least, Mitiga found that the SSM proxy feature can be abused to route the SSM traffic to an attacker-controlled server, including a non-AWS account endpoint, thereby permitting the threat actor to to commandeer the SSM Agent without having to rely on AWS infrastructure.

Organizations are recommended to remove the SSM binaries from the allow list associated with antivirus solutions to detect any signs of anomalous activity and ensure that EC2 instances respond to commands that only come from the original AWS account using the Virtual Private Cloud (VPC) endpoint for Systems Manager.

After controlling the SSM Agent, the attackers can carry out malicious activities, such as data theft, encrypting the filesystem (as a ransomware), misusing endpoint resources for cryptocurrency mining and attempting to propagate to other endpoints within the network – all under the guise of using a legitimate software, the SSM Agent, the researchers said.

 

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:16 pm, Mai 18, 2025
Wetter-Symbol 17°C
L: 15° | H: 18°
wenige Wolken
Luftfeuchtigkeit: 56 %
Druck: 1019 mb
Wind: 2 mph NNE
Windböe: 5 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 13%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:04 am
Sonnenuntergang: 8:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
15° | 18°°C 0 mm 0% 7 mph 63 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 55 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 6 mph 54 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0 mm 0% 6 mph 63 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,656.45
1.65%
Ethereum(ETH)
€2,266.00
2.70%
Fesseln(USDT)
€0.90
-0.01%
XRP(XRP)
€2.16
3.18%
Solana(SOL)
€154.73
3.55%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.201890
5.51%
Shiba Inu(SHIB)
€0.000013
5.68%
Pepe(PEPE)
€0.000012
9.16%
Peanut das Eichhörnchen(PNUT)
€0.312764
17.62%
Nach oben scrollen