Home / Blog / Attackers Are Running Their C2 on Your…
Cloud Security
Attackers Are Running Their C2 on Your Cloud, and You Are Paying for It
No fixed IP to block. No suspicious infrastructure for the SIEM to catch. The traffic belongs to Amazon and the invoice arrives at the end of the month - yours.
Attackers are running their command-and-control server on your cloud. And you are paying for it. Out of your own account.
What does that mean? Somebody breaks into your cloud environment. But instead of standing up a command-and-control server on some dubious VPS in Russia or Romania, they open a Lambda function in your AWS. Quiet, clean, entirely legitimate.
The traffic? Looks like ordinary organisational activity. The address? Belongs to Amazon. The invoice? Arrives with you at the end of the month.
It is like a burglar breaking into your house, ordering himself a pizza on your phone, and you paying for it without noticing.
The genius of it is the simplicity
A Lambda function needs no server. There is no fixed IP to block. There is no suspicious infrastructure for the SIEM systems to catch. The whole architecture runs on a service you yourself use every day.
Think about it from the attacker's point of view. Why pay for my own server when I can use yours? Why risk exposing my IP address when everything goes through Amazon? Why build infrastructure when the victim builds it for me?
This is not a bug. It is not a technical weakness. It is entirely legitimate use of a cloud service - and that is exactly what makes it so hard to identify.
Now double it
The attacker is not only attacking you. They are using your Lambda to attack somebody else. You are not just the victim; you are the unwitting accomplice. Your infrastructure is the weapon, and your account is paying for the ammunition.
What actually bothers me
Most of the organisations I know do not monitor the creation of new Lambda functions. There is no alert on it. There is nobody checking. There is no awareness at all that this is an attack vector.
They invest millions in firewalls and network defence - but the cloud? The cloud is treated like no-man's-land.
And if you are thinking this is not relevant to you because you do not use Lambda, think again. Every serverless service is exposed to this. Every cloud environment with loose permissions is a candidate.
If you are not monitoring what happens in your cloud account at the level of functions and services, you may be funding an attack without knowing it.
I first shared a version of this as a LinkedIn post on 2026-06-26. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
Keep reading
More from the blog
Cloud Security
Cloud Ransomware: Soft-Delete and Versioning Are the Whole Story
One over-permissioned Service Principal leaked through an old configuration, and we could read, delete, replace and encrypt every blob. The difference between…
Read itCloud Security
A Quarter of Azure Identities Trusting GitHub Actions Are Takeable. Right Now.
When a repo is deleted or a namespace freed, the OIDC trust policy stays. Anyone can re-register that namespace, get a valid…
Read itCloud Security
An Hour Into the Assessment We’re Cloud Admin – and It’s Never a Zero-Day
Most companies believe their cloud is secure because someone configured IAM policies and the CSPM shows green. We get admin inside an…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.