logo

Crypto crooks co-opt stolen AWS creds to mine coins

ID: a808b293-531b-59b7-95bd-39e4c93a5235

STIX ID: report--a808b293-531b-59b7-95bd-39e4c93a5235

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2025-12-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

AWS customers are being targeted by an ongoing cryptomining campaign that leverages stolen IAM credentials to rapidly deploy SBRMiner-MULTI across EC2 and ECS. Attackers probe service quotas, create numerous ECS clusters and auto-scaling groups to maximize resource usage, set DisableApiTermination on instances to hinder removal, and establish persistence via unauthenticated Lambda Function URLs; Amazon GuardDuty detected a number of affected accounts and Amazon recommends enforcing MFA, least privilege, and temporary credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.