Full Report
See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling
Analysis Summary
# Incident Report: Multi-Platform AWS and GitHub Credential Compromise
## Executive Summary
An external threat actor successfully compromised long-lived permanent access keys associated with a legacy CI/CD service account (`svc_automation`). Operating through commercial VPN nodes via Kali Linux, the attacker pivoted across multiple AWS accounts, executed remote code via AWS Systems Manager (SSM) on a production domain controller, and targeted connected GitHub source code repositories. The attack was autonomously investigated and correlated across cloud environments by the Wiz Blue Agent, enabling swift identification of the compromise vector and custom exfiltration tooling.
## Incident Details
- Discovery Date: September 29, 2026
- Incident Date: September 29, 2026
- Affected Organization: Not disclosed (Internal Case Study)
- Sector: Technology / Cloud Infrastructure
- Geography: Attacker origin geolocated to Taiwan (Zenlayer Inc.); Target infrastructure hosted globally/US.
## Timeline of Events
### Initial Access
- Date/Time: 09:52 UTC
- Vector: Valid Accounts (Compromised long-lived IAM access keys)
- Details: The attacker used a permanent access key belonging to a legacy 2018 CI/CD service account (`svc_automation`) to initiate an `AssumeRole` operation to a CI role. The request originated from a Zenlayer Inc. VPN exit node using a Kali Linux user agent.
### Lateral Movement
- 09:55 UTC: The attacker executed a second `AssumeRole` request to the same CI role from a distinct IP address within the Zenlayer range.
- Cross-Account Pivot: The attacker utilized a second, distinct permanent access key for the same `svc_automation` account to authenticate into a secondary AWS account within the organization's tenant.
- 10:06 UTC: The attacker achieved Remote Code Execution (RCE) by leveraging the `SSM SendCommand` API targeting a production domain controller instance named `PROD-*******-DC1`.
### Data Exfiltration/Impact
- Following the AWS infrastructure compromise, the attacker tracked paths into the organization's integrated GitHub environment.
- The attacker targeted and accessed proprietary source code and deployed custom data exfiltration tooling within the environment.
### Detection & Response
- **Detection**: The attack triggered three simultaneous AWS detection rules: *Unusual User Access Through Third-Party VPN*, *API Calls From Unusual Country*, and *AWS Management API Calls by a Known Offensive Tool*.
- **Response**: The autonomous SOC investigator (Blue Agent) immediately triaged the alerts, analyzed a 30-day historical baseline of the service account, identified cross-account deviations, and mapped the full cross-platform attack path across AWS and GitHub within minutes.
## Attack Methodology
- **Initial Access**: Valid Accounts (Compromised long-lived AWS IAM access keys).
- **Persistence**: Utilization of multiple permanent access keys across separate cloud environments.
- **Privilege Escalation**: Abuse of cloud administrative roles via `AssumeRole` actions.
- **Defense Evasion**: Traffic routing through anonymizing commercial hosting/VPN providers (Zenlayer Inc. / ExpressVPN).
- **Credential Access**: Exploitation of exposed static CI/CD infrastructure secrets.
- **Discovery**: Cloud infrastructure profiling and cross-account enumeration.
- **Lateral Movement**: Cloud cross-account pivoting and AWS Systems Manager (`SSM SendCommand`) abuse.
- **Collection**: Staging and targeting of organization source code repositories.
- **Exfiltration**: Deployment of custom data exfiltration tooling.
- **Impact**: Unauthorized administrative access to core production assets (Domain Controller) and potential source code exposure.
## Impact Assessment
- **Financial**: Undetermined; costs related to incident response, forensics, and remediation.
- **Data Breach**: Compromise of proprietary source code repositories via GitHub and potential exposure of Active Directory data.
- **Operational**: High operational risk due to compromised production systems, requiring immediate credential revocation and server isolation.
- **Reputational**: High risk if proprietary source code or customer data within the production environment is publicly leaked.
## Indicators of Compromise
- **Network Indicators**:
- Zenlayer Inc. / ExpressVPN routing nodes (Geolocated to Taiwan) [defanged: `Zenlayer[.]Inc`]
- **File/Host Indicators**:
- User Agent: `kali-amd64`
- User Agent: `aws-cli`
- **Behavioral Indicators**:
- `svc_automation` service account executing cloud operations from non-Amazon web hosting ASNs.
- Unexpected `AssumeRole` and `SSM SendCommand` invocations from a legacy CI/CD identity.
## Response Actions
- **Containment**: Immediately revoked all active sessions and permanent access keys associated with the `svc_automation` IAM account.
- **Eradication**: Isolated the affected production domain controller (`PROD-*******-DC1`) to inspect for web shells, persistence mechanisms, or secondary backdoors.
- **Recovery**: Rotated all connected third-party integrations and GitHub OAuth/access tokens associated with the compromised AWS environments.
## Lessons Learned
- **Static Credentials Risk**: Long-lived permanent access keys assigned to automated service accounts present a severe security vulnerability if exposed or leaked.
- **Monitoring Identity Baselines**: Establishing strict behavioral baselines for automated service accounts allows security tools to quickly flag deviations, such as an automation account suddenly using a Kali Linux user agent.
- **Cross-Platform Visibility**: Attacks today quickly transition from cloud infrastructure (AWS) to developer ecosystems (GitHub); siloed monitoring leaves critical blind spots.
## Recommendations
- **Eliminate Permanent Keys**: Transition CI/CD tools (e.g., TeamCity) from permanent AWS IAM access keys to short-lived OpenID Connect (OIDC) identities.
- **Implement IP Restraints**: Enforce Service Control Policies (SCPs) or IAM Conditional Access policies that restrict service account API calls exclusively to whitelisted corporate or CI/CD infrastructure IP spaces.
- **Enforce Least Privilege**: Restrict the permissions of CI/CD identities to prevent them from executing highly disruptive administrative actions like `ssm:SendCommand` against core production assets.