Threats/Threat ID: T-Z7bgh5
aws

Permissive Execution Permissions were Granted to Lambda Function

Medium
🕓 Last Seen 04-08-2026 · 4:00:22 PM|🗂 cyngular_client_1👤 Unassigned ▾● New ▾
View all IOC's
Enriched, correlated and triaged by the agent squad.
3 min
Time to resolution
0
Analyst touches
1
Consoles to pivot
6
Agents working
AI Summary Mesh live · agents collaborating1,284 inter-agent messages today

Cyngular uncovered a cloud threat where permissive execution permissions were granted to a Lambda function in AWS. The change was initiated by arn:aws:sts::528757810539:assumed-role/MaliciousEC2Role using the action AddPermission20150331v2 on arn:aws:lambda:us-west-2:…:MaliciousLambdaFunc, granting external account 248189932415 the right to invoke it. On its own the event reads Medium — but correlated with a leaked GitHub key, an impossible-travel Okta login and a downstream S3 policy change, the squad rates the overall campaign Critical: an external actor establishing persistence to stage data exfiltration.

How the squad worked this — one brain, six agents· click any agent to see just its activity
🧾 Evidence details
The raw CloudTrail log, auto-parsed
Export
Cloud Account ID
528757810539
Event ID
348812c1-e797-41ed-9a7e-856dd8daf400
Event Name
AddPermission20150331v2
Event Time
2026-08-05T16:00:22.253Z
Source IP Address
2.54.178.107EXTERNAL
Source IP Country
IL 🇮🇱
Source IP Domain Resolution
orange.net.il
Source IP Whois
Partner Communications Ltd
Source User Identity Arn
arn:aws:sts::528757810539:assumed-role/MaliciousEC2Role
Target Resource
arn:aws:lambda:us-west-2:528757810539:function:MaliciousLambdaFunc
Action
lambda:InvokeFunction
Added Account IDs
248189932415
Assumed Role
arn:aws:iam::528757810539:role/MaliciousEC2Role
Principal
arn:aws:iam::248189932415:root
Effect
AllowRISK
🕒 Attack timeline
This incident's kill-chain, in order
15:42Initial Access
Long-lived AWS access key committed to a public repo
Secret scanning flagged an AKIA… key pushed to infra-scripts (public).
15:47Initial Access
Impossible-travel sign-in for svc-deploy
Auth from Tel Aviv, IL — 9,300 km from the prior session in 11 min.
15:51Privilege Escalation
AssumeRole to MaliciousEC2Role from 2.54.178.107
Observer flagged the role assumption — this identity had never used it before.
15:55Execution
EC2 instance ran a suspicious script via UserData
i-0ab3f… executed a base64 payload that installed the AWS CLI and enumerated IAM.
15:58Credential Access
Credential-harvesting process tree on i-0ab3f…
Falcon flagged a child process reading instance-metadata credentials and beaconing to 2.54.178.107.
16:00:22PersistenceTHIS THREAT
Permissive execution permissions granted to Lambda function
AddPermission gave account 248189932415 lambda:InvokeFunction on MaliciousLambdaFunc.
16:00:36Deception
Attacker used decoy credentials against honey-db-02
Deceptor's honeypot confirmed hands-on-keyboard intent and upgraded severity.
16:03Persistence
Lambda config URL created · cross-account invoke
A public function URL was added and invoked from the external account.
16:04Correlation
Correlated into one incident — blast radius 3 hosts
Investigator stitched the GitHub leak, Okta travel, AssumeRole and this event into a single kill-chain.
16:06Exfiltration
S3 bucket policy modified to accept a wildcard account
cyngular-client-1-data opened to Principal:* — the staged exfil path.
16:08Exfiltration
Public exposure detected on cyngular-client-1-data
Wiz confirmed the bucket became internet-reachable, corroborating the exfil risk.
16:09Response
Auto-contained — role isolated, sessions revoked, IP blocked
Resolver quarantined MaliciousEC2Role, revoked 4 sessions and blocked 2.54.178.107 pending approval.