$ techbeacon▋
Threats

Hackers Exploit Signed Software and AWS API Gateway to Mask Reverse‑Shell Access

Hackers Exploit Signed Software and AWS API Gateway to Mask Reverse‑Shell Access

Security researchers have uncovered a sophisticated intrusion method that blends a fake IT‑support campaign with legitimate‑signed applications and Amazon Web Services (AWS) API Gateway to hide reverse‑shell traffic. The technique enables threat actors to gain remote control of compromised Windows systems while evading typical network‑monitoring tools.

The attack begins with a social‑engineering ploy that poses as technical support. Victims are coaxed into installing a malicious Microsoft Installer (MSI) package, which silently drops a payload capable of opening a reverse shell. Rather than routing this traffic directly, the malicious code tunnels the connection through an AWS API Gateway endpoint, a service commonly used for legitimate API management, thereby blending malicious traffic with normal cloud communications.

To further obscure their presence, the attackers embed the reverse‑shell functionality inside a legitimately signed executable. By leveraging code signing certificates that appear trustworthy, the malicious binary can bypass many endpoint‑security checks that rely on signature validation. Once the signed component is executed, it launches the hidden shell, allowing the adversary to issue commands on the compromised host without triggering alarms that look for unsigned or known‑malware binaries.

This layered approach reflects a growing trend where threat actors combine multiple legitimate services and tools to create “living‑off‑the‑land” attack chains. Using cloud infrastructure such as AWS API Gateway not only provides high availability and scalability but also places the malicious traffic within the same traffic patterns as normal business operations, making detection by conventional intrusion‑detection systems more difficult.

The findings were reported by the independent security group GBHackers, who emphasized that the method illustrates how attackers can fragment their operations across different stages—initial access, payload delivery, and command‑and‑control—while each stage appears benign in isolation. This modular design complicates incident response, as defenders must correlate disparate indicators across social engineering, signed binaries, and cloud service logs.

Experts advise organizations to strengthen verification processes for any unsolicited support requests, enforce strict controls on software signing certificates, and monitor outbound connections to cloud services for anomalous patterns. Enhanced logging of API Gateway usage, combined with behavioral analytics on Windows endpoints, can help uncover the covert reverse‑shell channels before attackers achieve deeper footholds. As adversaries continue to blend legitimate infrastructure with malicious code, a multi‑layered defense strategy becomes essential to mitigate these evolving threats.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related