Also known as: tracked as, Deed RAT, a variant of ShadowPad, entities in the defense, security sectors, Octo-Tempest, abusing valid credentials, manipulating MFA, re-attempt access, CVE-2025-61882, UAC-0001, UNC3944
Codefinger emerged as a cloud‑centric ransomware operator that targets Amazon S3 buckets with the intent of extortion. The gang leverages compromised AWS identities—often obtained through credential stuffing or phishing—to gain write access to victim buckets. By configuring encryption to use customer‑provided keys (SSE‑C) and subsequently encrypting stored objects, they effectively lock the data away and demand payment for the decryption key. Beyond S3, Codefinger is capable of launching multi‑stage attacks that begin with exploitation of known CVEs or zero‑day flaws in web applications and database services. Once inside a target environment, the actor employs remote code execution to install additional backdoors and may pivot to distributed cryptojacking on Apache WebLogic or other web servers. The group’s operational approach blends traditional ransomware delivery mechanisms, such as Cobalt Strike or RCE payloads, with cloud‑native techniques that manipulate S3 encryption. Persistence is often achieved through long‑lived AWS IAM roles and compromised credentials, allowing repeated opportunistic attacks across multiple accounts and regions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Codefinger is a financially motivated ransomware threat actor that exploits Amazon S3 buckets by abusing Server‑Side Encryption with Customer‑Provided Keys (SSE‑C). The group uses compromised AWS credentials and misconfigured bucket policies to encrypt data, demanding Bitcoin in exchange for decryption keys while threatening eventual deletion. Their tactics extend beyond cloud storage to include exploitation of web applications, CVE/zero‑day vulnerabilities, and peer‑to‑peer propagation.
Goals & Targeting
Codefinger’s strategic objective appears to be rapid financial gain through data extortion. Target selection spans the high‑value sectors listed—financial services, defense, government, healthcare, manufacturing, energy, and critical infrastructure—where any data loss directly translates to operational disruption or regulatory penalties. They exploit misconfigurations in cloud storage rather than sophisticated supply‑chain attacks, indicating a focus on opportunistic breaches rather than targeted espionage. The actor seeks victims with publicly accessible S3 buckets or weak IAM permissions, often those that have not enabled bucket lock or MFA delete controls. By exploiting AWS’s native encryption features, Codefinger can perform ransomware without installing additional payloads on the victim machine, reducing detection risk during the initial compromise. In addition to extortion, some activity hints at secondary objectives such as cryptojacking and credential harvesting via web application vulnerabilities, diversifying their revenue streams.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Codefinger’s campaign patterns demonstrate an opportunistic and rapid attack cadence. Incidents cluster around early 2025, with repeated attempts to encrypt S3 buckets within hours of identifying exposed credentials. Victims span a wide array of sectors, reflecting the group’s non‑sectoral approach that favors high-value cloud resources over industry-specific targets. Operational tempo is sustained but uneven, often following discovery of misconfigured IAM policies or newly disclosed CVEs in common web stacks such as Magento and Craft CMS. The actor typically drops a small cryptojacking payload to monetize residual access before launching the ransomware chain if the primary objective (data extortion) fails or stalls. Notable past operations include multiple data extortion incidents against U.S. financial institutions and defense contractors, where the group demanded Bitcoin for previously encrypted files stored in AWS S3 buckets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attribution of Codefinger to a financially motivated ransomware operation targeting AWS S3 buckets is moderate, based on converging reports and technical patterns. However, significant gaps remain regarding the actor’s full capabilities, precise timeline, attribution depth (human or state-sponsored), and whether they engage in other objective‑oriented campaigns beyond extortion. Further evidence from forensic artifacts and threat intelligence correlates would be required to elevate confidence.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
49
Tools
0
Campaigns
54
IOCs
0
Observed Data
3
Tactics