logo

Attackers Use Stolen AWS Credentials in Cryptomining Campaign

ID: c64f3a1e-13e7-5ade-a409-a33781487bfc

STIX ID: report--c64f3a1e-13e7-5ade-a409-a33781487bfc

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

AWS security teams detected a widespread cryptomining campaign where attackers leveraged compromised AWS IAM credentials to provision EC2 and ECS resources and deploy miners within ~10 minutes. The actors performed permission reconnaissance (GetServiceQuota, DryRun RunInstances), created service-linked and Lambda roles, attached execution policies, and used persistence by setting instance termination protection; AWS published IoCs (malicious Docker image yenik65958/secret, domains asia.rplant.xyz eu.rplant.xyz na.rplant.xyz, instance naming patterns) and recommended IAM hardening, MFA, temporary credentials, and CloudTrail monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.