Think AWS Traffic Is Safe? Meet HazyBeacon.

GTIS

Analyst

GTIS

Deployed

2026-06-21T11:10:14.517Z

Reading Time

5 min read

Think AWS Traffic Is Safe? Meet HazyBeacon.

Think your security tools can spot malicious traffic? HazyBeacon challenges that assumption. By weaponizing AWS Lambda Function URLs, attackers are hiding command-and-control communications behind trusted cloud infrastructure, making dangerous activity appear completely legitimate. As cybercriminals increasingly exploit the cloud itself, organizations must ask a critical question: If attackers can blend into your normal cloud traffic, would you even know they're there?

How Attackers Are Turning AWS Into a Cyber-Espionage Weapon

When Trust Becomes a Security Risk

Cyber threats are constantly evolving, and attackers are becoming increasingly skilled at hiding their operations within the very technologies organizations trust the most. A newly identified cyber-espionage campaign known as HazyBeacon demonstrates this shift by abusing AWS Lambda Function URLs to create covert command-and-control (C2) channels that blend seamlessly into legitimate cloud traffic. Unlike traditional malware that communicates with attacker-owned servers, HazyBeacon leverages trusted AWS infrastructure, making malicious activity significantly more difficult to detect and block.

Security researchers tracking the campaign, identified as CL-STA-1020, have observed attackers targeting government networks across Southeast Asia through a sophisticated cloud-native approach. Rather than exploiting vulnerabilities within AWS itself, the threat actors are taking advantage of stolen cloud credentials and misconfigured serverless services to transform legitimate cloud resources into stealth communication relays.

How HazyBeacon Operates

The attack begins with the compromise of AWS Identity and Access Management (IAM) credentials, which are often obtained through phishing campaigns, exposed repositories, or poorly secured development environments. Once attackers gain access, they create AWS Lambda functions within compromised cloud accounts and enable publicly accessible Function URLs configured without authentication requirements. These Lambda Function URLs act as intermediaries between infected devices and the attackers' actual command-and-control infrastructure. Instead of communicating directly with suspicious domains or IP addresses, compromised systems send encrypted requests to AWS-hosted endpoints. The Lambda functions then relay those requests to attacker-controlled servers and return responses back to the infected machines. This indirect communication method effectively hides the true destination of the traffic and allows malicious activity to blend into routine cloud communications. Because these requests travel through trusted AWS domains ending in on.aws, many traditional security tools perceive the traffic as legitimate. This creates a significant challenge for defenders who have historically relied on domain reputation, IP blacklists, and perimeter-based monitoring to identify malicious communications.

A Shift Toward Cloud-Native Command and Control

HazyBeacon represents a growing trend in modern cyber operations where attackers leverage legitimate cloud platforms instead of building dedicated infrastructure. By embedding their operations within trusted services, threat actors gain several advantages, including improved stealth, lower operational costs, greater scalability, and a reduced likelihood of detection. This approach reflects a broader evolution in cybercrime. As organizations continue migrating critical workloads to the cloud, attackers are increasingly focusing on identity abuse and cloud misconfigurations rather than traditional software vulnerabilities. The result is a new generation of threats that exploit trust rather than technical weaknesses.

Why Organizations Should Be Concerned

The effectiveness of HazyBeacon lies in its ability to hide in plain sight. Since communications appear to originate from legitimate AWS infrastructure, many security solutions struggle to distinguish malicious traffic from normal business operations. This allows attackers to maintain persistence, collect sensitive information, execute remote commands, and exfiltrate data without triggering conventional security alerts. Researchers have also noted that unusual Lambda deployments, unexpected public Function URLs, suspicious API activity, unexplained increases in Lambda invocations, and abnormal cloud spending patterns may all indicate attempts to establish cloud-based command-and-control channels. These subtle indicators often go unnoticed in environments lacking comprehensive cloud visibility.

Strengthening Defenses Against Cloud-Based Threats

Defending against campaigns like HazyBeacon requires a security strategy that prioritizes identity protection, visibility, and continuous monitoring. Organizations should enforce strong IAM security practices, regularly rotate access keys, implement multi-factor authentication, and apply the principle of least privilege across cloud environments. Comprehensive logging through services such as CloudTrail, CloudWatch, and VPC Flow Logs can provide valuable insight into unauthorized activity and suspicious configuration changes.

Equally important is restricting the creation of publicly accessible Lambda Function URLs unless explicitly approved through governance policies. Security teams should also adopt behavioral monitoring techniques capable of detecting unusual API calls, unexpected resource deployments, and anomalous traffic patterns that may indicate malicious activity operating within trusted cloud services.

The Future of Cloud Security

HazyBeacon serves as a powerful reminder that cloud platforms can become attractive operational environments for attackers when identity controls and configuration management are neglected. The campaign highlights the growing importance of cloud security visibility and demonstrates that trust alone is no longer a reliable security model. As cloud adoption continues to accelerate, organizations must shift their focus from traditional perimeter defenses toward identity-centric security frameworks that continuously monitor access, behavior, and configuration changes. In modern cloud environments, every API call tells a story, and the ability to understand that story may be the difference between detecting a threat early and allowing infrastructure to become a weapon in the hands of cybercriminals.

GTIS Security Insight

"In today's cloud-first world, attackers no longer need to build malicious infrastructure—they simply hide inside trusted platforms. Strong identity controls, continuous monitoring, and complete visibility remain the foundation of effective cloud security."

Contact us Today .

Cloud SecurityAWS SecurityHazyBeaconThreat IntelligenceCybersecurityIAM SecurityServerless SecurityCloud InfrastructureCommand and Control (C2)Threat Detection
Distribute Intel

Share Report

End of Transmission
Next Steps

Ready to Strengthen
Your Security Posture?

Our team of cybersecurity experts is ready to help you navigate the evolving threat landscape. Get in touch for a tailored security assessment.