This dangerous new malware wants to target your cloud systems

Magnifying glass enlarging the word 'malware' in computer machine code



(Image credit: Shutterstock)

Researchers from SentinelLabs have uncovered a new toolkit cybercriminals are using to breach email and web hosting (opens in new tab) services. 

The malware toolkit, called “AlienFox”, is being described as “highly modular” and getting regular updates. Most of the tools in the kit are open source, and with the speed at which it’s being updated, the researchers concluded the devs are becoming “increasingly sophisticated”.

As per SentinelLabs’ report, hackers are shilling AlienFox on Telegram groups, claiming it can be used to compromise misconfigured hosts on cloud platforms and steal sensitive data.

Abusing scanning platforms 

“AlienFox tools facilitate attacks on minimal services that lack the resources needed for mining,” the researchers said in their report. “By analyzing the tools and tool output, we found that actors use AlienFox to identify and collect service credentials from misconfigured or exposed services. For victims, compromise can lead to additional service costs, loss of customer trust, and remediation costs.”

To generate a list of misconfigured hosts, the toolkit uses security scanning platforms, such as LeakIX, or SecurityTrails. Then, it uses multiple scripts to pull sensitive information such as API keys and secrets from configuration files, the researchers explained. Some of the versions analyzed for the report were able to establish AWS account persistence and escalate privileges, as well as collect send quotas and automate spam campaigns through victim accounts and services.

So far, attacks against cloud-based services were limited mostly to cryptominers. Threat actors would use compromised cloud servers to run XMRig or similar cryptocurrency miners, generating tokens without needing to pay for electricity, internet, or compute power. With AlienFox, SentinelLabs claims, opportunistic cloud attacks are no longer confined to cryptomining. 

“For victims, compromise can lead to additional service costs, loss in customer trust, and remediation costs,” the researchers concluded.

Via: The Register (opens in new tab) 

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More
Rebecka Roberie

Latest

Martin Scorsese has officially joined the AI camp and it’s not what anyone expected

Martin Scorsese has partnered with AI startup Black Forest Labs to use generative AI for storyboarding Martin Scoresese Everett Collection / Shutterstock.com Hollywood’s complicated romance with artificial intelligence just got a whole lot more interesting. Martin Scorsese, the 83-year-old director behind Goodfellas, Raging Bull, and The Departed, has signed on as a partner and adviser

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release

President Trump signed an executive order on Tuesday establishing a voluntary framework for government review of frontier AI models before public release, ending weeks of internal White House conflict over how aggressively to regulate the technology. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” was signed privately without the usual livestream or public ceremony, a

Poland will introduce a “sovereignty test” for government tech purchases as Tusk warns AI dependency has reached dangerous proportions

TL;DR Polish PM Donald Tusk announced a “sovereignty test” for significant government technology purchases and annual IT independence reports, warning that Poland’s dependency on foreign digital infrastructure demands urgent policy action. Polish Prime Minister Donald Tusk has announced that Poland will introduce a “sovereignty test” for significant government purchases of technology solutions, warning that the

How small businesses can leverage AI

Case study Sam Finnegan-Dehn works in fundraising for a charity, but he moonlights as a math and philosophy tutor for university students from his home in London. Through this part-time business, he can leverage his degrees in philosophy and share his love of the subject with clients. But meeting with students is only a fraction

Newsletter

Don't miss

Martin Scorsese has officially joined the AI camp and it’s not what anyone expected

Martin Scorsese has partnered with AI startup Black Forest Labs to use generative AI for storyboarding Martin Scoresese Everett Collection / Shutterstock.com Hollywood’s complicated romance with artificial intelligence just got a whole lot more interesting. Martin Scorsese, the 83-year-old director behind Goodfellas, Raging Bull, and The Departed, has signed on as a partner and adviser

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release

President Trump signed an executive order on Tuesday establishing a voluntary framework for government review of frontier AI models before public release, ending weeks of internal White House conflict over how aggressively to regulate the technology. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” was signed privately without the usual livestream or public ceremony, a

Poland will introduce a “sovereignty test” for government tech purchases as Tusk warns AI dependency has reached dangerous proportions

TL;DR Polish PM Donald Tusk announced a “sovereignty test” for significant government technology purchases and annual IT independence reports, warning that Poland’s dependency on foreign digital infrastructure demands urgent policy action. Polish Prime Minister Donald Tusk has announced that Poland will introduce a “sovereignty test” for significant government purchases of technology solutions, warning that the

How small businesses can leverage AI

Case study Sam Finnegan-Dehn works in fundraising for a charity, but he moonlights as a math and philosophy tutor for university students from his home in London. Through this part-time business, he can leverage his degrees in philosophy and share his love of the subject with clients. But meeting with students is only a fraction

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they