Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Crimson Collective

Crimson Collective

TLP:CLEAR
Active

Also known as: CryptoChameleon, Octo Tempest, UNC3944, tracked as, hold it for ransom, Scattered Spider, SLSH, ShinyHunters

Description

Crimson Collective has positioned itself as a sophisticated threat actor that exploits misconfigurations in cloud environments, especially AWS, to gain long‑term persistence. They routinely search for exposed IAM keys with TruffleHog, create new users or elevate privileges by attaching permissive policies, and then pivot into higher‑value assets such as RDS databases. By leveraging native AWS services—exposing RDS snapshots to S3 buckets, using Amazon Simple Email Service (SES) to deliver extortion notes, and exploiting WinRM endpoints—they can exfiltrate data and conduct ransomware campaigns with minimal detectability. The group also demonstrates a broader attack surface by deploying AI‑powered phishing pages via Softr against Microsoft Exchange/OWA, targeting Cisco products in CVE‑2025‑20393 and CVE‑2023‑20198, and using a mix of public‑facing exploits (e.g., drive‑by compromises) and legitimate tools like PsExec, anyDesk, and mshta. Crimson Collective’s campaigns are highly lucrative: they target finance, healthcare, retail, defense and other strategic sectors in the U.S., France, and Japan. They frequently leverage high‑profile corporate accounts to extort victims for cash or cryptocurrency while quietly exfiltrating sensitive data through cloud channels.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Hospitality
Defense
Telecommunications
Retail
Media
Aviation
Government
Education
Manufacturing

Targeted Countries / Regions

US
FR
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

Crimson Collective is a financially driven cyber‑criminal group that leverages cloud infrastructures—particularly AWS—for data exfiltration and extortion. In September 2025 they announced a massive breach of Red Hat’s private GitHub repositories, claiming 570 GB and dozens of customer engagement reports. Their tactics combine credential theft, privilege escalation, and the use of native cloud services to stealthily move laterally and exfiltrate data while demanding ransoms via Amazon SES.

Goals & Targeting

The actor’s primary objective is monetary gain via a hybrid model of ransomware and data‐theft‑extortion. By compromising long‑term IAM credentials they can establish persistent, high‑privilege access to target AWS environments where they identify valuable data stored in RDS, S3, or other services. Target selection focuses on large enterprises with complex cloud footprints—particularly those operating in finance, healthcare, retail and defense sectors across the U.S., France and Japan—to maximize payout potential while minimizing exposure and increasing the likelihood of a profitable ransom negotiation.

Enhanced Description

Key Capabilities

  • Compromise long‑term IAM access keys to gain persistence
  • Create new IAM users or attach permissive policies for privilege escalation
  • Recon within compromised AWS environments to identify valuable data stores
  • Exfiltrate data by exporting RDS snapshots to S3 buckets using native services
  • Leverage Amazon SES to deliver extortion notes and orchestrate ransomware campaigns
  • Discover leaked credentials with TruffleHog across code repositories
  • Deploy AI‑powered Softr phishing pages targeting Microsoft Exchange/OWA
  • Exploit Cisco CVE‑2025‑20393 and CVE‑2023‑20198 to increase foothold
  • Abuse exposed WinRM ports for lateral movement
  • Conduct active scanning of target firewalls (e.g., ASA) to locate vulnerable services

MITRE ATT&CK Tactics

Credential Access
Privilege Escalation
Discovery
Collection
Exfiltration
Command And Control
Impact
Initial Access
Reconnaissance
Execution

ATT&CK Techniques

T1053.005
T1003.002
T1069.003
T1204.002
T1530
T1074.002
T1070.003
T1190
T1567
T1219
T1580
T1595
T1548
T1589.002
T1003.005
T1619
T1021.007
T1087.004
T1059.001
T1136.003
T1593
T1566
T1078
T1068
T1556.006
T1578.005
T1059.006
T1578.002
T1213.003
T1505
T1189
T1059.005
T1526
T1578.001
T1003.003
T1204.001
T1078.004
T1556
T1562.001
T1070.001

Software / Tooling

TruffleHog
Softr
PsExec
mshta.exe
AnyDesk
Hive

Campaigns & Victims

Crimson Collective operates on a repeatable framework that capitalizes on cloud misconfigurations and public‑facing services. Campaigns are typically initiated with credential discovery using TruffleHog, followed by stealthy lateral movement within AWS and the exploitation of exposed management interfaces such as WinRM and WorkMail. Data harvesting is performed via native snapshot exports to S3, and exfiltration is complemented by malicious web service usage (SNS/SSE) or direct transfer to staging buckets. The group has demonstrated repeat attacks against Red Hat’s customers and is suspected to maintain a partnership network that includes other ransomware labs for data‑theft‑extortion operations. Victims are mainly large enterprises in high‑value sectors across the U.S., France, and Japan, with an operational tempo of several weeks per engagement.

IOC Patterns

  • Leaked AWS long‑term access keys discovered via TruffleHog
  • IAM privilege escalation by creating new users or attaching permissive policies
  • RDS master password changes via ModifyDBInstance API
  • Exporting RDS snapshots to S3 buckets for data exfiltration
  • Abnormal Amazon SES email traffic used for extortion notes
  • Exploitation of CVE‑2025‑20393 and CVE‑2023‑20198 in Cisco products
  • Open WinRM ports exposed on the internet
  • Use of auxiliary SES accounts to send legit-looking phishing emails
  • Credential harvesting AI pages via Softr

Recommended Actions

  • Enforce least privilege on IAM roles; block long‑term access keys in favor of STS temporary credentials
  • Enable IAM guardrails to detect creation of new users or privilege escalation attempts
  • Restrict ModifyDBInstance and other sensitive RDS permissions; monitor snapshot export activity to S3 buckets
  • Audit and secure S3 bucket policies used for data staging and exfiltration
  • Monitor SES usage for anomalous email send rates or ransom note patterns
  • Patch vulnerabilities CVE‑2025‑20393 and CVE‑2023‑20198 immediately; harden Cisco assets
  • Secure WinRM ports; restrict inbound access to essential services only
  • Deploy advanced email filtering, anti‑phishing, and AI‑based credential harvesting detection solutions
  • Implement continuous monitoring of cloud resource changes using native audit logs and SIEM integration

Suggested Tags

AWS
IAM
RDS
S3
SES
TruffleHog
Credential Theft
Data Exfiltration
Extortion
Open-source Credential Scanning
Phishing
CredentialHarvesting
AI-based phishing
ValidAccounts
AWSAbuse
CVEExploitation
WinRMExploit
ActiveScanning
RedHat
CiscoVulnerability

Confidence Assessment

The evidence base for Crimson Collective’s activities is a mix of verified company statements, security vendor reports, and publicly disclosed CVEs. While multiple independent sources corroborate their use of cloud credential exploitation and extortion tactics, direct attribution to the group remains largely dependent on claim‑based disclosures (e.g., Red Hat’s notification). Key gaps persist around the full scale of compromised assets, successful ransom collections, and exact timelines across distinct incidents.

ATT&CK Techniques

Command & Control
1 technique
Exfiltration
1 technique
Lateral Movement
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 IPv4 Address 5 Email Address 4

References

  1. unit42.paloaltonetworks.com — Cited by web research for: hold it for ransom
  2. blog.talosintelligence.com — Cited by web research for: T1078
  3. www.rapid7.com — Cited by web research for: T1580
  4. www.rapid7.com — Cited by web research for: Global
  5. www.vectra.ai — Cited by web research for: STOP
  6. research.checkpoint.com — Cited by web research for: MgBot
  7. https://www.redhat.com/en/press-release/red-hat-reports-data-breach — Cited by AI analysis.
  8. https://www.rapid7.com/blog/post/2025/09/15/crimson-collective-attempts-ransomware-on-red-hat — Cited by AI analysis.
  9. https://nvd.nist.gov/vuln/detail/CVE‑2025‑20393 — Cited by AI analysis.
  10. https://nvd.nist.gov/vuln/detail/CVE‑2023‑20198 — Cited by AI analysis.

Intel Summary

40

Techniques

43

Tools

0

Campaigns

26

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Data Exfiltration
APT group
Cyber espionage
Supply chain attack
Software development sector
Data theft
Intellectual property theft
AWS
IAM
RDS
S3
SES
TruffleHog
Credential Theft
Extortion
Open-source Credential Scanning
Phishing
CredentialHarvesting
AI-based phishing
ValidAccounts
AWSAbuse
CVEExploitation
WinRMExploit
ActiveScanning
RedHat
CiscoVulnerability

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United Arab Emirates (AE)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.