PT-2021-23636 · Undefined · Undefined

Published

2021-10-26

·

Updated

2025-10-08

·

CVE-2021-42572

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
#ParsedReport #CompletenessLow 07-10-2025
Crimson Collective: A New Threat Group Observed Operating in the Cloud
Report completeness: Low
Actors/Campaigns: Crimson collective
Threats: Trufflehog tool
Victims: Cloud service providers, Technology sector
Geo: Ukraine, Russia
CVEs: CVE-2021-42572 [Vulners] CVSS V3.1: Unknown, Vulners: Exploitation: Unknown X-Force: Risk: Unknown X-Force: Patch: Unknown
TTPs: Tactics: 4 Technics: 15
IOCs: Coin: 1 IP: 4
Functions: GetCalletIdentity, CreateUser, CreateLoginProfile, CreateAccessKey, SimulatePrincipalPolicy, AttachUserPolicy, GetUser, GetAccount, GetBucketLocation, GetHostedZoneCount, have more...
Win API: GetObject

Related Identifiers

CVE-2021-42572

Affected Products

Undefined