{"id":7448,"date":"2025-10-06T10:03:27","date_gmt":"2025-10-06T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/06\/hackers-weaponize-aws-x-ray-service-to-work-as-covert-command-control-server\/"},"modified":"2025-10-06T10:03:27","modified_gmt":"2025-10-06T10:03:27","slug":"hackers-weaponize-aws-x-ray-service-to-work-as-covert-command-control-server","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/06\/hackers-weaponize-aws-x-ray-service-to-work-as-covert-command-control-server\/","title":{"rendered":"Hackers Weaponize AWS X-Ray Service to Work as Covert Command &amp; Control Server"},"content":{"rendered":"\n<div>Hackers Weaponize AWS X-Ray Service to Work as Covert Command &#038; Control Server<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated technique uncovered where threat actors abuse <a href=\"https:\/\/cybersecuritynews.com\/aws-patches-multiple-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Web Services<\/a>\u2018 X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be weaponized for malicious purposes.<\/p>\n<p>AWS X-Ray, designed to help developers analyze application performance through distributed tracing, has been repurposed by <a href=\"https:\/\/cybersecuritynews.com\/generative-ai-in-red-teaming\/\" target=\"_blank\" rel=\"noreferrer noopener\">red team<\/a> researchers into a steganographic communication channel called XRayC2.\u00a0<\/p>\n<p>This technique leverages X-Ray\u2019s annotation system, which allows arbitrary key-value data storage, to transmit commands and exfiltrate data through legitimate AWS API calls to xray.[region].amazonaws.com endpoints.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-weaponizing-aws-x-ray-for-covert-command-and-control\"><strong>Weaponizing AWS X-Ray for Covert Command and Control<\/strong><\/h2>\n<p>According to Dhiraj, the attack methodology exploits X-Ray\u2019s trace segments functionality, where malicious payloads are embedded within seemingly benign monitoring data.\u00a0<\/p>\n<p>Attackers utilize the service\u2019s PutTraceSegments, GetTraceSummaries, and BatchGetTraces API endpoints to establish bidirectional communication channels that blend seamlessly with legitimate cloud traffic.<\/p>\n<p>The implant establishes presence through beacon markers containing system information encoded in trace annotations, including service type identifiers like \u201chealth_check\u201d and unique instance identifiers.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"491\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-25.png?resize=625%2C491&#038;ssl=1\" alt=\"Command Delivery (Controller \u2192 Implant)\" class=\"wp-image-129004\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-25.png 625w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-25-300x236.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-25-535x420.png 535w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-25-150x118.png 150w\" sizes=\"(max-width: 625px) 100vw, 625px\"><figcaption class=\"wp-element-caption\">Command Delivery (Controller \u2192 Implant)<\/figcaption><\/figure>\n<\/div>\n<p>Command delivery occurs through base64-encoded payloads stored in configuration annotations, while result exfiltration leverages execution_result fields within trace data structures.<\/p>\n<p>This technique <a href=\"https:\/\/medium.com\/@dhiraj_mishra\/ghost-in-the-cloud-weaponizing-aws-x-ray-for-command-control-7539d60f1d77\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">demonstrates<\/a> sophisticated evasion capabilities by implementing custom AWS Signature Version 4 (SigV4) authentication, creating legitimate AWS API traffic that integrates naturally with standard network logs.\u00a0<\/p>\n<p>The malicious communication employs randomized beacon intervals between 30 and 60 seconds and utilizes HMAC-SHA256 signing with access keys, following Amazon\u2019s canonical request format.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"642\" height=\"489\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26.png?resize=642%2C489&#038;ssl=1\" alt=\"Result Exfiltration (Implant \u2192 Controller)\" class=\"wp-image-129005\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26.png 642w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26-300x229.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26-551x420.png 551w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26-80x60.png 80w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-26-150x114.png 150w\" sizes=\"(max-width: 642px) 100vw, 642px\"><figcaption class=\"wp-element-caption\">Result Exfiltration (Implant \u2192 Controller)<\/figcaption><\/figure>\n<\/div>\n<p>The XRayC2 toolkit requires minimal AWS permissions, utilizing the AWSXRayDaemonWriteAccess policy alongside custom permissions for trace manipulation.\u00a0<\/p>\n<p>This approach significantly reduces the attack surface compared to traditional <a href=\"https:\/\/cybersecuritynews.com\/salat-stealer-exfiltrates-browser-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">C2 infrastructure<\/a> while maintaining persistent access through cloud-native services.<\/p>\n<p>Detection of this technique presents challenges for security teams, as the malicious traffic appears as standard application performance monitoring activities.\u00a0<\/p>\n<p>Organizations should implement enhanced monitoring of X-Ray API usage patterns, establish baseline metrics for trace annotation data volumes, and scrutinize unusual service interactions within their AWS environments to identify potential abuse of legitimate <a href=\"https:\/\/cybersecuritynews.com\/cloudflare-warp-hijack\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud services<\/a> for covert communications.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponize-aws-x-ray-service\/\">Hackers Weaponize AWS X-Ray Service to Work as Covert Command &amp; Control Server<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponize-aws-x-ray-service\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Weaponize AWS X-Ray Service to Work as Covert Command &#038; Control Server A sophisticated technique uncovered where threat actors abuse Amazon Web Services\u2018 X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be weaponized for malicious purposes. AWS X-Ray, designed to help developers analyze application [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-7448","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7448"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7448"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7448\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}