Cyber attacks in the cloud take less than ten minutes to launch
New research into cyber attacks in the cloud has shown that on average it takes less than ten minutes to launch an attack after first discovering credentials. The finding concerned targeted attacks, where cyber criminals chose their targets for a specific reason, such as having a misconfiguration in their cloud environment that could be exploited.
Of the ten minutes it took from finding a working credential to launching the attack, five of them were dwell time.
When cyber criminals can enter a cloud environment and launch an attack at such pace, it becomes extremely difficult for defenders to detect the intrusion and prevent the attack from taking place. During opportunistic attacks – those without a specific target – it took cyber criminals on average less than two minutes to find a publicly exposed credential after scanning for a vulnerability, like a misconfiguration. It then took an average of 21 minutes for them to initiate an attack.
Researchers at Sysdig attributed the speed of attacks to the weaponization of automation, warning that attackers are focusing on identity and access management (IAM) with evolving techniques for credential access, privilege escalation, and lateral movement.
The increasing emphasis on ‘everything as code’ in the cloud environment has contributed to the difficulties defenders face. Serverless function code and infrastructure-as-code (IaC) software such as CloudFormation and Terraform were said to be of particular interest to attackers since the files can contain credentials or secrets but might be overlooked by security scans.
What is in your supply chain?
Researchers also considered the state of containers. After analyzing 13,000 Docker hub images, researchers found 819 were malicious. However, 10% of those were undetectable, thanks to advanced techniques to hide malicious code. Only at runtime could the threat be detected.
What are the targets and what are the goals?
Nearly two-thirds (65%) of cloud attacks target the telecommunications and finance sectors specifically. Other goals include resource hijacking, where an attacker will seek to quickly monetize an asset by spinning up cryptomining instances and leveraging existing instances to launch new attacks.
Mitigation and trends
Defending against and mitigating attacks requires a multi-pronged approach. As the cloud continues to move toward everything-as-code and container technologies, complexity will continue to increase, and attackers will take advantage of any mistakes made.
Source: Cyber attacks in the cloud take less than ten minutes to launch | ITPro


