Traditional C2 setups depend on attacker-controlled servers and generate detectable anomalies—suspicious domains, unknown IP addresses, irregular traffic patterns, and certificate oddities.
XRayC2 instead leverages AWS X-Ray’s built-in annotation feature to embed encrypted key-value data within trace segments, routing all communications through legitimate AWS domains such as xray.<region>.amazonaws.com.
This method blends malicious payloads with standard monitoring data, thwarting detection tools that focus solely on traffic origin or volume.
The toolkit uses three distinct phases:
Deploying XRayC2 requires an AWS Identity and Access Management user provisioned with “AWSXRayDaemonWriteAccess” and custom permissions for PutTraceSegments, GetTraceSummaries, and BatchGetTraces across all resources.
The toolkit auto-generates zero-dependency implants for macOS, Linux, and Windows, enabling straightforward deployment without additional software.
The controller UI offers comprehensive implant management, listing active hosts, selecting targets, issuing commands, and viewing implant status while maintaining persistence via X-Ray’s infrastructure.
XRayC2’s abuse of a trusted cloud service highlights the evolution of stealthy attack vectors.
must expand monitoring beyond network-level indicators to include:
Combining these measures with traditional threat intelligence and anomaly detection solutions will be critical for identifying and mitigating cloud-based C2 operations.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates
The post Hackers Abuse AWS X-Ray as Covert Command-and-Control Channel appeared first on Cyber Security News.
Between the ubiquitous virtual assistants cheerfully patronising us from almost every electronic device and the…
If you're a Windows user who's looking for a PC version of the Apple Mac…
FORT WAYNE, Ind. (WOWO) — The state of Indiana has agreed to let the Indiana…
FORT WAYNE, Ind. (WOWO) — Severe thunderstorms are expected to move across central Indiana in…
Universal Pictures and Focus Features have taken the stage at CinemaCon. We're expecting new looks…
Maritza Montejo, a Liberty Tax Service office manager, helps Aurora Hernandez, left, with her taxes…
This website uses cookies.