Security Posture Report - August 2025
Alibaba Cloud Platform Security Posture Report for August 2025
1. Platform attack and defense status
Default platform defense metrics
Daily average in August 2025
Attacks blocked: 4.6 billion, a 2.6% decrease from July
Blocked attacker IP addresses: 26,000, a 12.4% decrease from July

DDoS attack mitigation
In August, the Alibaba Cloud platform detected and blocked the following:
39,000 DDoS attacks, a 66% decrease from July
Peak DDoS attack traffic of 1,600 Gbps, a 6.7% increase from July

2. Recent attack methods and trends
Hackers use stolen AccessKeys and Cloud Assistant to plant back doors for malicious activities
Recently, the Alibaba Cloud security team detected large-scale DDoS attacks originating from Elastic Compute Service (ECS) instances across multiple Alibaba Cloud accounts. Our analysis revealed that attackers gained unauthorized access to these accounts by stealing user AccessKeys (AKs). The attackers then used Cloud Assistant to install stealthy back doors on multiple instances. By activating these back doors, they launched large-scale attacks. We have named this group ShadowSpear because of its expertise in stealthy infiltration and long-term persistence.
Attack method
Initial compromise: Attackers obtain user AKs by exploiting vulnerabilities, leveraging misconfigurations, or using social engineering. This allows them to control the ECS instances in the compromised account.
Back door installation: After a successful breach, the attackers use the Alibaba Cloud Cloud Assistant feature to execute commands or upload files on the compromised hosts. Cloud Assistant is an automated Operations and Maintenance (O&M) tool for Alibaba Cloud ECS that supports batch command execution, file uploads, and templated operations without requiring a logon to the system.
Camouflage and persistence: To evade detection, the attackers store the malicious program in an Object Storage Service (OSS) bucket that they control. They name the file `AliYun_Dunupdate` to disguise it as an "Alibaba Cloud Security update program" and trick users into thinking it is an official component. The file is then downloaded and installed as a persistent back door process.
Remote activation and attack: When ready to launch an attack, the attackers remotely load the attack program through the back door. They use the network resources of the compromised ECS instances to launch large-scale DDoS attacks. This method allows for low-cost and highly concealed attack scheduling.
Indicators of Compromise (IOCs)
Related samples
b61c939f2c40e595d5066cb2ab079bd5
a9d50858143c13f4eb752a03ba20bcbe
e9e00b5e045d5bd517af60bfb175dcb3
1ecea2ca6ff87ce4bb83737395ca4216
C2 addresses
38.45.125.146
38.46.14.2
38.46.14.90
aliyunassistclientsinglelock.net
alIyUN.duNUPdaTe.com
Security recommendations
Respond promptly to abnormal AccessKey alerts
If you receive an "Abnormal AccessKey Call" or "Restrictive Protection Alert" from Alibaba Cloud, you should immediately verify whether the AccessKey has been compromised. You can check the relevant API call logs, especially command records executed using Cloud Assistant, to detect and block abnormal operations.
Remediate infected hosts promptly
If you confirm that a system has a back door or you receive a back door alert from Alibaba Cloud, you can enable the Host Protection - Virus Scan feature in Security Center. You can then perform a full scan of the server to identify and purge malicious programs and enhance system security.
Alibaba Cloud provides a free quota for the basic Anti-virus Edition of Security Center to every user. You can go to the Free Trial Center to claim it.
3. Frequently attacked vulnerabilities
Based on attack data analytics, the Alibaba Cloud security team has identified vulnerabilities that are frequently scanned and exploited in the cloud environment. If your assets are affected, we recommend that you promptly detect and remediate these vulnerabilities or implement protective measures.
No. | Vulnerability | ID | Free detection supported |
1 | Critical NestJS DevTools RCE vulnerability | No | |
2 | Docker daemon API unauthorized access vulnerability | No | |
3 | PHP CGI remote code execution vulnerability on Windows | Yes | |
4 | PHP < 7.1.32 PHP-FPM misconfiguration remote code execution vulnerability | No | |
5 | Redis unauthorized access vulnerability | Yes | |
6 | Apache Log4j2 remote code execution vulnerability | Yes | |
7 | Apache RocketMQ remote code execution vulnerability | Yes | |
8 | Hadoop YARN REST API command execution vulnerability | No | |
9 | Apache ActiveMQ remote code execution vulnerability | No | |
10 | Gogs symbolic link remote command injection vulnerability | No |
Free detection is available for some of these vulnerabilities. You can go to the Alibaba Cloud Security Management console, enable the free security assessment, and scan for emergency vulnerabilities.