AWS S3 Bucket Malware Redirect

The AWS S3 bucket hosting the KrustyLoader malware was being directed to by multiple MS-ISAC member organizations.

Bottom line: Security teams must verify AWS S3 bucket configurations and DNS traffic to prevent KrustyLoader malware infections.

What's happening: The Cybersecurity and Infrastructure Security Agency (CISA) reported that MS-ISAC members were directing DNS traffic to AWS S3 buckets hosting the KrustyLoader malware. Researchers at Google Cloud (CVE-2023-6331) discovered the malicious traffic. The malicious traffic was observed on March 15, 2023, and continued through March 17, 2023.

What to do: Security teams must review AWS S3 bucket configurations and DNS traffic to ensure they are not inadvertently directing traffic to malicious buckets. They should also implement DNS security measures, such as DNS traffic filtering, to block malicious traffic.

Source: CIS Blog