Forgotten AWS Access Keys Remain Valid Long After Their Workload Is Gone
AWS IAM user access keys do not expire automatically and stay valid until someone explicitly deletes or deactivates them, creating a persistent security risk even after the workloads they served are retired. Palo Alto Networks Unit 42 documented this danger through the EleKtra-Leak campaign, in which threat actors continuously scanned public GitHub repositories for exposed AWS credentials. In controlled tests, a leaked plaintext key was detected and exploited within five minutes, with attackers attempting to spin up EC2 instances for cryptocurrency mining. Between August 30 and October 6, 2023, researchers observed 474 distinct miners linked to the campaign, which had been active since at least 2020. Security experts recommend replacing long-lived IAM keys with temporary credentials via IAM roles, federated identity, or OIDC where possible, and treating any remaining persistent keys as explicit, documented exceptions with defined retirement conditions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in