Suspicious AWS IAM User Creation Using Support Impersonation Name

PremiumReviewedSigma · High · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-05-20
Updated
2026-08-28

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the creation of an AWS IAM user named aws_support which the TeamTNT Doppelganger campaign creates and grants administrative permissions to in order to establish a persistent privileged foothold disguised as a legitimate AWS support account.

Related detections4 linkedT1136.003 — drag to rearrange
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
GitHub Audit Log: New Organization Member Added or Invited
M365 Exchange Add-FederatedDomain Success: New Federated Domain Created
AWS CloudTrail: ElastiCache Cache Security Group Created
Suspicious AWS IAM User Creation Using Support Impersonation Name
Pivot detection · T1136.003 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.