Suspicious activity

MFA virtual device was delete from Tor IP address

Platform(s)

Description

Orca detected that an API call to 'DeleteVirtualMFADevice' was made from a tor IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, since deleting a virtual MFA device for specific user, may help to impersonate the user more easily and abuse its permissions.