PT-2021-23636 · Undefined · Undefined
Published
2021-10-26
·
Updated
2025-10-08
·
CVE-2021-42572
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
#ParsedReport #CompletenessLow
07-10-2025
Crimson Collective: A New Threat Group Observed Operating in the Cloud
Report completeness: Low
Actors/Campaigns:
Crimson collective
Threats:
Trufflehog tool
Victims:
Cloud service providers, Technology sector
Geo:
Ukraine, Russia
CVEs:
CVE-2021-42572 [Vulners]
CVSS V3.1: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
TTPs:
Tactics: 4
Technics: 15
IOCs:
Coin: 1
IP: 4
Functions:
GetCalletIdentity, CreateUser, CreateLoginProfile, CreateAccessKey, SimulatePrincipalPolicy, AttachUserPolicy, GetUser, GetAccount, GetBucketLocation, GetHostedZoneCount, have more...
Win API:
GetObject
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined