Attackers Use Stolen AWS Credentials in Cryptomining Campaign
ID: c64f3a1e-13e7-5ade-a409-a33781487bfc
STIX ID: report--c64f3a1e-13e7-5ade-a409-a33781487bfc
Feed Name: Dark Reading
Date Published: 2025-12-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
AWS security teams detected a widespread cryptomining campaign where attackers leveraged compromised AWS IAM credentials to provision EC2 and ECS resources and deploy miners within ~10 minutes. The actors performed permission reconnaissance (GetServiceQuota, DryRun RunInstances), created service-linked and Lambda roles, attached execution policies, and used persistence by setting instance termination protection; AWS published IoCs (malicious Docker image yenik65958/secret, domains asia.rplant.xyz eu.rplant.xyz na.rplant.xyz, instance naming patterns) and recommended IAM hardening, MFA, temporary credentials, and CloudTrail monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
