heroui logo

Potential Tunneling via AWS IoT Secure Tunneling Localproxy

Elastic Detection Rules

View Source
Summary
Detects potential use of AWS IoT Secure Tunneling localproxy in destination mode, which creates a bidirectional tunnel through AWS infrastructure and forwards streams to a local service (e.g., SSH on 127.0.0.1:22). The rule correlates three events from the same process within 5 minutes: (1) a process start where the binary is localproxy (or localproxy.exe) invoked with destination mode flags (-d/--destination-app or -m dst/destination with a config directory), (2) a DNS query to data.tunneling.iot.<region>.amazonaws.com, and (3) an outbound TCP/443 connection from the same process. In destination mode the agent connects to the data plane; source mode would open a loopback listener on the operator workstation. The OpenTunnel artifact and tokens reside in the attacker’s AWS account, not on the victim, indicating post-exploitation C2 activity rather than initial access. The rule covers cross-platform behavior and expects the official or renamed localproxy binary with appropriate flags; web proxies may obscure DNS/443 signals. False positives may occur from legitimate device-management or support activity using the same binary and flags, so exceptions should be limited to known assets. Remediation steps include isolating the host, terminating localproxy, blocking the tunneling data-plane hostname, removing dropped binaries and config files, and investigating what services were connected through the tunnel. Organizations not using Secure Tunneling should keep the rule enabled and block the data-plane endpoint.
Categories
  • Network
  • Endpoint
  • AWS
  • IoT
  • Cloud
  • Windows
  • Linux
  • macOS
Data Sources
  • Process
  • Network Traffic
ATT&CK Techniques
  • T1071
  • T1071.001
  • T1090
  • T1090.002
  • T1572
Created: 2026-09-18