All Research Stories•Cloud Security

From a Forgotten S3 Token to Full AWS Root: Anatomy of a Real-World Cloud Takeover

A step-by-step forensic breakdown of an attack chain escalating an unprivileged S3 read token to full AWS organization root control via STS assume-role abuse.

SR
Samantha Roy
Jul 15, 2026•7 min read•18,740 reads
From a Forgotten S3 Token to Full AWS Root: Anatomy of a Real-World Cloud Takeover
Figure: Architectural breakdown and technical analysis · The Exploit Company

Anatomy of an AWS IAM Escalation: From Stale S3 Key to Root Control

During a recent simulated enterprise adversary engagement, our offensive security engineers gained initial footholds through a forgotten, read-only IAM access key embedded in an abandoned CI/CD pipeline.

Within four hours, this low-privilege read token was escalated into full organization-level root access across seventy AWS accounts. Here is the exact step-by-step forensic breakdown of how the privilege escalation occurred.

Cloud identity is the new enterprise perimeter. In complex multi-account environments, trust relationships between roles are frequently the most vulnerable lateral movement pathways.

The Multi-Step Escalation Chain

  • **Step 1: Stale S3 Read Token:** The compromised key had permission to read a single internal configuration bucket containing encrypted terraform state files.
  • **Step 2: KMS Decryption & AssumeRole:** The state file revealed the ARN of a cross-account deployment role that possessed excessive `sts:AssumeRole` trust policies.
  • **Step 3: Permission Boundary Misconfiguration:** The assumed role was permitted to attach managed policies to lambda service roles without enforcing an existing IAM permission boundary.
  • **Step 4: AdministratorAccess Execution:** A temporary Lambda function was created with full administrative privileges, granting persistent administrative access.
  • Critical Remediation Steps

    Every organization running multi-account cloud estates should implement the following guardrails:

  • Enforce rigorous IAM Access Analyzer rules to detect stale credentials inactive for more than thirty days.
  • Mandate SCP (Service Control Policy) boundary assertions that prevent non-root accounts from modifying administrative role trust documents.
  • Require external ID and MFA assertions on all cross-account trust relationships.
  • AWS IAMINCIDENT RESPONSECLOUD SECURITYPRIVILEGE ESCALATION
    SR
    Published by
    Samantha Roy
    Cloud Security Lead specializing in AI security guardrails, systems architecture, and engineering at The Exploit Company.