Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Codefinger

Also known as: tracked as, Deed RAT, a variant of ShadowPad, entities in the defense, security sectors, Octo-Tempest, abusing valid credentials, manipulating MFA, re-attempt access, CVE-2025-61882, UAC-0001, UNC3944

Description

Codefinger emerged as a cloud‑centric ransomware operator that targets Amazon S3 buckets with the intent of extortion. The gang leverages compromised AWS identities—often obtained through credential stuffing or phishing—to gain write access to victim buckets. By configuring encryption to use customer‑provided keys (SSE‑C) and subsequently encrypting stored objects, they effectively lock the data away and demand payment for the decryption key. Beyond S3, Codefinger is capable of launching multi‑stage attacks that begin with exploitation of known CVEs or zero‑day flaws in web applications and database services. Once inside a target environment, the actor employs remote code execution to install additional backdoors and may pivot to distributed cryptojacking on Apache WebLogic or other web servers. The group’s operational approach blends traditional ransomware delivery mechanisms, such as Cobalt Strike or RCE payloads, with cloud‑native techniques that manipulate S3 encryption. Persistence is often achieved through long‑lived AWS IAM roles and compromised credentials, allowing repeated opportunistic attacks across multiple accounts and regions.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Healthcare
Education
Telecommunications
Manufacturing
Mining
Transportation
Critical infrastructure
Energy
Hospitality
Information technology
Media
Utilities
Non profit

Targeted Countries / Regions

US
CN
TW
AE
DE
GB
KP
JP
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Codefinger is a financially motivated ransomware threat actor that exploits Amazon S3 buckets by abusing Server‑Side Encryption with Customer‑Provided Keys (SSE‑C). The group uses compromised AWS credentials and misconfigured bucket policies to encrypt data, demanding Bitcoin in exchange for decryption keys while threatening eventual deletion. Their tactics extend beyond cloud storage to include exploitation of web applications, CVE/zero‑day vulnerabilities, and peer‑to‑peer propagation.

Goals & Targeting

Codefinger’s strategic objective appears to be rapid financial gain through data extortion. Target selection spans the high‑value sectors listed—financial services, defense, government, healthcare, manufacturing, energy, and critical infrastructure—where any data loss directly translates to operational disruption or regulatory penalties. They exploit misconfigurations in cloud storage rather than sophisticated supply‑chain attacks, indicating a focus on opportunistic breaches rather than targeted espionage. The actor seeks victims with publicly accessible S3 buckets or weak IAM permissions, often those that have not enabled bucket lock or MFA delete controls. By exploiting AWS’s native encryption features, Codefinger can perform ransomware without installing additional payloads on the victim machine, reducing detection risk during the initial compromise. In addition to extortion, some activity hints at secondary objectives such as cryptojacking and credential harvesting via web application vulnerabilities, diversifying their revenue streams.

Enhanced Description

Key Capabilities

  • Encrypt files stored in Amazon S3 buckets using SSE‑C for ransomware
  • Target cloud storage assets for data extortion
  • Exploit compromised AWS credentials and misconfigured IAM roles
  • Leverage Server‑Side Encryption with Customer‑Provided Keys (SSE‑C) in S3 operations
  • Deploy ransomware via exploitation of database or web application vulnerabilities
  • Use peer‑to‑peer infection mechanisms to spread malware
  • Exploit known CVE and zero‑day vulnerabilities in enterprise software
  • Persist through remote code execution on legacy and cloud platforms

MITRE ATT&CK Tactics

Impact
Command and Control

ATT&CK Techniques

T1486
T1021
T1041

Software / Tooling

Cobalt Strike
ShadowSyndicate
Lucifer Botnet
P2PInfect
Cl0p Ransomware
DripDropper Malware
RedTail Cryptomining
RUBYCARP
AWS CLI

Campaigns & Victims

Codefinger’s campaign patterns demonstrate an opportunistic and rapid attack cadence. Incidents cluster around early 2025, with repeated attempts to encrypt S3 buckets within hours of identifying exposed credentials. Victims span a wide array of sectors, reflecting the group’s non‑sectoral approach that favors high-value cloud resources over industry-specific targets. Operational tempo is sustained but uneven, often following discovery of misconfigured IAM policies or newly disclosed CVEs in common web stacks such as Magento and Craft CMS. The actor typically drops a small cryptojacking payload to monetize residual access before launching the ransomware chain if the primary objective (data extortion) fails or stalls. Notable past operations include multiple data extortion incidents against U.S. financial institutions and defense contractors, where the group demanded Bitcoin for previously encrypted files stored in AWS S3 buckets.

IOC Patterns

  • Amazon S3 bucket name patterns linked to Codefinger activity
  • Use of SSE‑C in S3 requests
  • Patterns indicating misconfigured IAM roles or lack of MFA delete
  • File names such as MyCustomKeyNowEncrypted.bin and Fangao.dll
  • Domains ending with amazonaws.com
  • Domains related to cloud infrastructure (e.g., aws.amazon.com, aws.s3.amazonaws.com)

Recommended Actions

  • Enforce MFA delete on all Amazon S3 buckets and audit bucket policies for least privilege IAM roles
  • Monitor S3 access logs for abnormal SSE‑C usage and rapid encryption activity
  • Implement automated alerts for sudden increases in write operations to S3 objects
  • Require strong, unique long‑term credentials for AWS accounts and rotate keys regularly
  • Educate users on phishing risks, especially emails containing links or attachments that could compromise AWS security credentials

Suggested Tags

ransomware
cloud storage
Amazon S3
SSE-C
data encryption
Codefinger
cryptojacking
credential abuse
CVE exploitation
zero‑day
peer‑to‑peer infection
AWS security
financial extortion

Confidence Assessment

Confidence in the core attribution of Codefinger to a financially motivated ransomware operation targeting AWS S3 buckets is moderate, based on converging reports and technical patterns. However, significant gaps remain regarding the actor’s full capabilities, precise timeline, attribution depth (human or state-sponsored), and whether they engage in other objective‑oriented campaigns beyond extortion. Further evidence from forensic artifacts and threat intelligence correlates would be required to elevate confidence.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 1 URL 3 Domain 16

References

  1. www.recordedfuture.com — Cited by web research for: Deed RAT
  2. www.trendmicro.com — Cited by web research for: GitHub
  3. threats.wiz.io — Cited by web research for: Rootkit
  4. www.fortinet.com — Cited by web research for: LockBit
  5. threats.wiz.io — Cited by web research for: wiz.io
  6. www.vectra.ai — Cited by web research for: support@vectra.ai

Intel Summary

3

Techniques

49

Tools

0

Campaigns

54

IOCs

0

Observed Data

3

Tactics

Tags

Ransomware
AWS
Cloud Security
Data Extortion
S3 Exploitation
ransomware
cloud storage
Amazon S3
SSE-C
data encryption
Codefinger
cryptojacking
credential abuse
CVE exploitation
zero‑day
peer‑to‑peer infection
AWS security
financial extortion

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.