Abusing The Public Cloud Apt Style
After A few discussions with a friend and just being bored last night I came up with this harebrained idea that I though an APT group…
Abusing The Public Cloud Apt Style
After A few discussions with a friend and just being bored last night I came up with this harebrained idea that I though an APT group could or would employ to remain stealth and have almost an Air gapped type malware that Doesn’t require the modern C2 environment that is prone to the usual takedowns etc. Now because I do not want to contribute to any malicious actions I want to leave out what I think would exist like network mapping file enumeration and automatic exfiltration. Imagine the situation where an APT group wants to send a targeted attack at a select group or just en masse they are constantly getting pwned taken down so my mind starts spinning what could they do to use something public and fast with some form of fault tolerance so the data is replicated to so many hosts it cant be take offline at 1 time.
When I say Fault tolerant I mean a lot of files are large and may not be easy for an attacker to transfer. They might want to mess with the warrant canary system knowing that chaining certain hosts from different countries that do not take so kindly to take down or to actually remove the data per request. The thing here it is physical impossible for you to attribute something like this ethically and actually stop it as if the data is encrypted properly You are not going to know what the data is meaning I could exfil 1 thousand files store them across 50 60 elastic searches diff ids etc you really can’t know for sure if it is me you wouldn’t want to go deleting peoples files illegally and shit it’s encrypted like I Said you have no clue what I have stored across the Elastics and it protects the victim lol these are 100% theoretical I did not have not and will not use any of your boxes to commit a crime you need to shut the ports and I am so tired of having to report data breaches and leaks of companies via elastic that i’m finally gonna bring to light what could be done besides being a dick and ransomware being used grow up CRACKERS stop infecting shit with ransomware and locking peoples shit and deleting it.
So I present a method to store a file across multiple elastic search clusters the real way I envisioned this was to have a implant that listened on the host for files to be created etc and upload them to elastic if discovered like password files secrets etc but than decided against demoing anything so weaponized as the code is enough to already Start a few issues but I Will do my best to leave it attributable en masse for researchers and not go to crazy but you do have to admit it is kind of badass.
You would load a file of elastic servers responding and check their ability to be replicated to by creating an indice and than storing the ip that allowed the creation globally and than using those ips that were able to store the initial index we would clean the artifacts up and grab the files and than exfiltrate them encrypted across the elastics and keep the ids as well as a few other fields for inserts etc still just a POC of course i do not want to go too far but this is my path of thinking hope u guys like it.
메타데이터
- post_id
- 1ea1d3d4cf1e
- slug
- abusing-the-public-cloud-apt-style-1ea1d3d4cf1e
- url
- https://medium.com/@wabafet/abusing-the-public-cloud-apt-style-1ea1d3d4cf1e
- canonical_url
- https://medium.com/@wabafet/abusing-the-public-cloud-apt-style-1ea1d3d4cf1e
- author_url
- https://medium.com/@wabafet
- status
- ok
- fetched_at
- 2026-07-29 02:21:17