AWSDetection & ResponseRetrospectives

Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2025, written in 2026 with the benefit of hindsight.

Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.

Signals worth watching

  • PutObject or CopyObject requests using SSE-C (customer-provided key headers), especially if your organization doesn't use SSE-C.
  • A single identity rewriting many objects in a short time.
  • PutBucketLifecycleConfiguration setting short expiration on existing objects.
  • PutBucketVersioning suspending versioning.
  • Deletion of object versions or backups.
  • New objects resembling ransom notes.
  • GuardDuty S3 Protection findings.

Where the data lives

  • CloudTrail S3 data events (enable for critical buckets; they're not on by default).
  • CloudTrail management events for lifecycle and versioning changes.
  • GuardDuty findings.

A starting query

SSE-C usage:

AWSCloudTrail
| where EventSource == "s3.amazonaws.com" and EventName in ("PutObject", "CopyObject")
| where RequestParameters has "x-amz-server-side-encryption-customer-algorithm"
| summarize Objects = count() by UserIdentityArn, SourceIpAddress, bin(TimeGenerated, 15m)

Lifecycle and versioning changes:

AWSCloudTrail
| where EventName in ("PutBucketLifecycle", "PutBucketLifecycleConfiguration", "PutBucketVersioning")
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters

Response

  1. Deactivate the credentials immediately.
  2. Remove malicious lifecycle rules.
  3. Restore previous object versions or backups.
  4. Investigate how the credentials were obtained.
detect s3 ransomware sse-cCodefinger SSE-C ransomware2025

More on this story