BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: CloudBashing: Exploiting free CloudShells for mining
 \,\n   networking\, exfil\, and persistence at scale\n   Tags: DEF CON Off
 icial Talk | Demo ðŸ’» | Tool ðŸ› \n   When: Friday\, Aug 7\, 16:30 - 17:3
 0 PDT\n   Where: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]M
 ap\n\n   Description:\n\n   CloudBashing started with reversing the privat
 e AWS\, Azure\, and GCP\n   CloudShell REST and websocket terminal protoco
 ls\, then tracing and\n   analyzing janky browser authentication/credentia
 l flows from cookies\n   to OAuth tokens. Along the way\, we automated the
  APIs to access free\n   CPU/networking\, maintained access across contain
 er/VM resets\, utilized\n   persistent $HOME for implants/data\, locked us
 ers out of sudo access\,\n   and installed a C2 framework. We discovered I
 AM design issues like:\n   AWS role assumption that result in a large # of
  environments per\n   compromised identity\, web socket sessions that surv
 ive API token\n   revocation\, and M365/Gmail consumer email accounts that
  have default\n   CloudShell access. This turned into a newly released exp
 loit toolkit\,\n   CloudBasher\, that enumerates\, validates\, installs\, 
 and runs\n   distributed workloads with virtual storage and private networ
 king\n   across a large-scale agent network with persistence and resilienc
 e.\n   We'll demo distributing CPU-intensive workloads\, using virtual sto
 rage\n   for staging/exfiltration\, secure networking for proxy and obfusc
 ated\n   exfil paths\, while automating the discovery\, enumeration\, crea
 tion of\n   CloudShell environments from initial credentials/sessions to\n
    implants/setup/networking to management and control.\n\n   Amazon Web S
 ervices\, "AWS CloudShell service authorization reference\,"\n   https://d
 ocs.aws.amazon.com/service-authorization/latest/reference/list_awscloudshe
 ll.html\n\n   Amazon Web Services\, "AWS Systems Manager StartSession API 
 (SSM\n   framing basis)\,"\n   https://docs.aws.amazon.com/systems-manager
 /latest/APIReference/API_StartSession.html\n\n   Google Cloud\, "Cloud She
 ll API v1 REST reference\,"\n   https://docs.cloud.google.com/shell/docs/r
 eference/rest/v1/users.environments\n\n   Microsoft Azure\, "Azure Cloud S
 hell overview\,"\n   https://docs.microsoft.com/en-us/azure/cloud-shell/ov
 erview\n\n   OSRU @ ronin.ae\, "AWS CloudShell analysis: privileged contai
 ner\,\n   exposed block devices and container escape(s)\," October 23\, 20
 23\,\n   https://web.archive.org/web/20240912135502/https://ronin.ae/news/
 aws-cloudshell-analysis/\n\n   Aidan Steele\, "Deep dive into AWS CloudShe
 ll\," awsteele.com\, January\n   11\, 2024\,\n   https://awsteele.com/blog
 /2024/01/11/deep-dive-into-aws-cloudshell.html\n\n   Paul Schwarzenberger\
 , "CloudShell slip-up: command-line access to\n   underlying AWS infrastru
 cture\," Medium\, October 15\, 2024\,\n   https://medium.com/@paulschwarze
 nberger/cloudshell-slip-up-command-line-access-to-underlying-aws-infrastru
 cture-ae77a0858088\n\n   Rhino Security Labs\, "AWS CloudShell Lateral Mov
 ement\,"\n   https://rhinosecuritylabs.com/aws/cloudshell-lateral-movement
 /\n\n   Eduard Agavriloae\, "notyet: AWS IAM Credential Revocation Gaps\,"
 \n   offensai\,\n   https://www.offensai.com/blog/notyet-aws-iam-credentia
 l-revocation-gaps\n\n   Dan Vittegleo\, cloudshell-store\, GitHub Reposito
 ry\,\n   https://github.com/dan-v/cloudshell-store\n\n   FrancescoDiSalesG
 ithub\, "Google-cloud-shell-hacking\," GitHub\n   Repository\,\n   https:/
 /github.com/FrancescoDiSalesGithub/Google-cloud-shell-hacking\n\n   Bipin 
 Jitiya\, "Google Cloud Shell Container Escape\," Medium\, December\n   14\
 , 2025\,\n   https://medium.com/@win3zz/google-cloud-shell-container-escap
 e-b69ffb46b5df\n\n   Bertrand Martel\, "AWS SSM Session: JavaScript librar
 y for AWS Systems\n   Manager Session Manager\," GitHub\,\n   https://gith
 ub.com/bertrandmartel/aws-ssm-session\n\n   Amazon Web Services\, "Amazon 
 SSM Agent: agentmessage.go\," AWS GitHub\n   Repository\,\n   https://gith
 ub.com/aws/amazon-ssm-agent/blob/c65d8ac29a8bbe6cd3f7cea778c1eeb1b06d49a3/
 agent/session/contracts/agentmessage.go\n\n   SentinelOne\, "CVE-2026-3216
 9: Azure Cloud Shell SSRF Vulnerability\,"\n   SentinelOne Vulnerability D
 atabase\, March 19\, 2026\,\n   https://www.sentinelone.com/vulnerability-
 database/cve-2026-32169/\n\n   Speakers:Jenko "edleft" Hwong\,Chris Ryan\n
 \n   SpeakerBio:  Jenko "edleft" Hwong\, Huntress Labs\n\n   Jenko Hwong i
 s a Principal Security Researcher at Huntress Labs\,\n   focusing on ident
 ity-based attacks and cloud abuse. Prior to Huntress\,\n   he spent 6 year
 s at Netskope Threat Labs\, has spoken at RSA and\n   DEFCON\, and is a Cl
 oud Village Lead. He has over 20 years at various\n   security startups in
  cloud detection/response\, vulnerability scanning\,\n   AV/AS\, pen-testi
 ng/exploits\, L3/4 appliances\, threat intel\, and\n   windows security.\n
 \n   SpeakerBio:  Chris Ryan\, Huntress Labs\n\n   A series of oddly confi
 gured server banners\, a JARM fingerprint\,\n   curious fields in a securi
 ty certificate - these aren't just technical\n   details\, but are instead
  threads in a narrative tapestry woven like a\n   John le Carre novel. For
  over 20 years\, Chris has dedicated his life\n   to studying these thread
 s and the intersection between cybersecurity\,\n   Russian linguistics\, a
 nd free and open source software. His career\n   path has taken detours th
 rough academia\, aerospace and defense\,\n   software development\, and cy
 bersecurity.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T003000Z
DTSTART:20260807T233000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:CloudBashing: Exploiting free CloudShells for mining\, networking\,
  exfil\, and persistence at scale
END:VEVENT
END:VCALENDAR
