Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries
Retrospective: this article looks back at events from January 2025, written in 2026 with the benefit of hindsight.
Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.
Signals worth watching
PutObjectorCopyObjectrequests using SSE-C (customer-provided key headers), especially if your organization doesn't use SSE-C.- A single identity rewriting many objects in a short time.
PutBucketLifecycleConfigurationsetting short expiration on existing objects.PutBucketVersioningsuspending versioning.- Deletion of object versions or backups.
- New objects resembling ransom notes.
- GuardDuty S3 Protection findings.
Where the data lives
- CloudTrail S3 data events (enable for critical buckets; they're not on by default).
- CloudTrail management events for lifecycle and versioning changes.
- GuardDuty findings.
A starting query
SSE-C usage:
AWSCloudTrail
| where EventSource == "s3.amazonaws.com" and EventName in ("PutObject", "CopyObject")
| where RequestParameters has "x-amz-server-side-encryption-customer-algorithm"
| summarize Objects = count() by UserIdentityArn, SourceIpAddress, bin(TimeGenerated, 15m)
Lifecycle and versioning changes:
AWSCloudTrail
| where EventName in ("PutBucketLifecycle", "PutBucketLifecycleConfiguration", "PutBucketVersioning")
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters
Response
- Deactivate the credentials immediately.
- Remove malicious lifecycle rules.
- Restore previous object versions or backups.
- Investigate how the credentials were obtained.
- Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS's Own SSE-C Incident Teardowns
- How to Block SSE-C Usage and Protect S3 With Versioning and Object Lock How-To & Hardening
- CIO Brief: Cloud-Native Ransomware Doesn't Need Malware CIO Briefings