← Back to news

The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs

Qualys Blog02/06/2026, 16:00
Read full article →

Summary

AI-Generated

Key Points:

  • HazyBeacon (CL-STA-1020) targets Southeast Asian government networks by exploiting AWS Lambda Function URLs configured with AuthType: NONE for stealth command-and-control operations.
  • The impact includes compromised cloud accounts, unauthorized data exfiltration, and difficulty in attribution due to the use of legitimate AWS infrastructure as a relay for malware communications.
  • Recommended actions include enforcing identity-centric access controls, enabling CloudTrail logging, restricting public Lambda Function URLs, and implementing Service Control Policies to mitigate exposure.

Technical Details: The HazyBeacon campaign utilizes stolen IAM credentials to deploy Lambda functions that proxy malware communications through trusted AWS domains. This approach allows attackers to blend malicious traffic with legitimate cloud activity.

MITRE ATT&CK Techniques:

  • T1078.004 - Valid Accounts: Cloud Accounts (Initial Access)
  • T1648 - Serverless Execution (Execution)
  • T1564 - Hide Artifacts (Defense Evasion)
  • T1102 - Web Service (Command and Control)
  • T1090 - Proxy (Command and Control)

IOCs Mentioned: None mentioned.

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.