CodefingerCodefinger

Also known as: Codefinger

Known aliases
1

Profile

Codefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. They utilize compromised AWS credentials to gain access and demand Bitcoin ransoms for the decryption keys, threatening to delete files if negotiations fail. The group has been observed abusing publicly disclosed AWS keys with permissions to read and write S3 objects, making recovery impossible without their cooperation. Halcyon has documented multiple incidents linked to Codefinger's data extortion campaign against organizations with unsecured infrastructure.

Aliases· 1

Codefinger

References

  1. https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
CoderCrypt
Software
LittleFinger
Actor
Sinobi
Software
SifreCozucu
Actor
EC2 Grouper
Actor
JavaGhost
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.