The CIS Cyber Threat Intelligence (CTI) team identified several MS-ISAC members directing DNS traffic to AWS S3 buckets hosting KrustyLoader.
KrustyLoader is a downloader that retrieves an encrypted Sliver payload from a second S3 location, injects it into Windows Explorer, and erases itself from disk.
This leaves the cyber threat actors (CTAs) with immediate covert access to victims’ systems.
Several of the identified S3 buckets remained active as of July 2026 and appeared to abuse legitimate companies' cloud storage accounts.
Learn how to be vigilant by reading the CIS CTI team's analysis.
Source: r/u/CISecurity · by /u/CISecurity