Talk

NotC2: Trusted by Default, Malicious by Design - AWS-Native Notifications as C2

NotC2: Trusted by Default, Malicious by Design - AWS-Native Notifications as C2

conf 2026-11-06 14:05 – 14:35 EN

NotC2: Trusted by Default, Malicious by Design - AWS-Native Notifications as C2

NotC2 is a post-compromise command-and-control framework built entirely on native AWS services, including SQS, Lambda, and SNS, with Amazon Bedrock serving as an AI-driven command interpreter. By relying exclusively on trusted cloud components, the framework avoids many of the traditional indicators associated with attacker infrastructure: there are no custom servers, suspicious domains, or conventional beaconing patterns. In this architecture, tasking is delivered through managed queueing services, executed serverlessly, and returned through cloud-native notification mechanisms-blending offensive activity into legitimate AWS traffic that is often implicitly trusted by enterprise environments. This creates significant visibility gaps for defenders, particularly where logging and telemetry do not fully capture service-level abuse by default. By integrating Bedrock, we also remove the need for traditional command-line tasking: operators can issue instructions in natural language, and the model translates them into actions. This shifts attacker tradecraft away from familiar CLI-based patterns and weakens many of the detection strategies built around command execution monitoring. In this talk, we will demonstrate the full attack chain, examine what defenders can realistically observe in their logs and cloud telemetry, and discuss practical detection opportunities, monitoring improvements, and hardening strategies for securing enterprise cloud environments against this emerging class of abuse.