Security Posture Report - August 2025

更新时间:
复制 MD 格式

Alibaba Cloud Platform Security Posture Report for August 2025

1. Platform attack and defense status

Default platform defense metrics

Daily average in August 2025

  • Attacks blocked: 4.6 billion, a 2.6% decrease from July

  • Blocked attacker IP addresses: 26,000, a 12.4% decrease from July

image.png

DDoS attack mitigation

In August, the Alibaba Cloud platform detected and blocked the following:

  • 39,000 DDoS attacks, a 66% decrease from July

  • Peak DDoS attack traffic of 1,600 Gbps, a 6.7% increase from July

image.png

2. Recent attack methods and trends

Hackers use stolen AccessKeys and Cloud Assistant to plant back doors for malicious activities

Recently, the Alibaba Cloud security team detected large-scale DDoS attacks originating from Elastic Compute Service (ECS) instances across multiple Alibaba Cloud accounts. Our analysis revealed that attackers gained unauthorized access to these accounts by stealing user AccessKeys (AKs). The attackers then used Cloud Assistant to install stealthy back doors on multiple instances. By activating these back doors, they launched large-scale attacks. We have named this group ShadowSpear because of its expertise in stealthy infiltration and long-term persistence.

Attack method
  1. Initial compromise: Attackers obtain user AKs by exploiting vulnerabilities, leveraging misconfigurations, or using social engineering. This allows them to control the ECS instances in the compromised account.

  2. Back door installation: After a successful breach, the attackers use the Alibaba Cloud Cloud Assistant feature to execute commands or upload files on the compromised hosts. Cloud Assistant is an automated Operations and Maintenance (O&M) tool for Alibaba Cloud ECS that supports batch command execution, file uploads, and templated operations without requiring a logon to the system.

  3. Camouflage and persistence: To evade detection, the attackers store the malicious program in an Object Storage Service (OSS) bucket that they control. They name the file `AliYun_Dunupdate` to disguise it as an "Alibaba Cloud Security update program" and trick users into thinking it is an official component. The file is then downloaded and installed as a persistent back door process.

  4. Remote activation and attack: When ready to launch an attack, the attackers remotely load the attack program through the back door. They use the network resources of the compromised ECS instances to launch large-scale DDoS attacks. This method allows for low-cost and highly concealed attack scheduling.

Indicators of Compromise (IOCs)
  1. Related samples

    1. b61c939f2c40e595d5066cb2ab079bd5

    2. a9d50858143c13f4eb752a03ba20bcbe

    3. e9e00b5e045d5bd517af60bfb175dcb3

    4. 1ecea2ca6ff87ce4bb83737395ca4216

  2. C2 addresses

    1. 38.45.125.146

    2. 38.46.14.2

    3. 38.46.14.90

    4. aliyunassistclientsinglelock.net

    5. alIyUN.duNUPdaTe.com

Security recommendations
  • Respond promptly to abnormal AccessKey alerts

If you receive an "Abnormal AccessKey Call" or "Restrictive Protection Alert" from Alibaba Cloud, you should immediately verify whether the AccessKey has been compromised. You can check the relevant API call logs, especially command records executed using Cloud Assistant, to detect and block abnormal operations.

  • Remediate infected hosts promptly

If you confirm that a system has a back door or you receive a back door alert from Alibaba Cloud, you can enable the Host Protection - Virus Scan feature in Security Center. You can then perform a full scan of the server to identify and purge malicious programs and enhance system security.

Alibaba Cloud provides a free quota for the basic Anti-virus Edition of Security Center to every user. You can go to the Free Trial Center to claim it.

3. Frequently attacked vulnerabilities

Based on attack data analytics, the Alibaba Cloud security team has identified vulnerabilities that are frequently scanned and exploited in the cloud environment. If your assets are affected, we recommend that you promptly detect and remediate these vulnerabilities or implement protective measures.

No.

Vulnerability

ID

Free detection supported

1

Critical NestJS DevTools RCE vulnerability

CVE-2025-54782

No

2

Docker daemon API unauthorized access vulnerability

AVD-2021-346121

No

3

PHP CGI remote code execution vulnerability on Windows

CVE-2024-4577

Yes

4

PHP < 7.1.32 PHP-FPM misconfiguration remote code execution vulnerability

CVE-2019-11043

No

5

Redis unauthorized access vulnerability

AVD-02021-0344

Yes

6

Apache Log4j2 remote code execution vulnerability

CVE-2021-44228

CVE-2021-45046

Yes

7

Apache RocketMQ remote code execution vulnerability

CVE-2023-33246

Yes

8

Hadoop YARN REST API command execution vulnerability

CVE-2021-33036

No

9

Apache ActiveMQ remote code execution vulnerability

CVE-2023-46604

No

10

Gogs symbolic link remote command injection vulnerability

CVE-2024-56731

No

Free detection is available for some of these vulnerabilities. You can go to the Alibaba Cloud Security Management console, enable the free security assessment, and scan for emergency vulnerabilities.