Tales from the cloud trenches: Amazon ECS is the new EC2 for crypto mining
ID: 0f934424-b586-5e97-9be4-563bfff7e529
STIX ID: report--0f934424-b586-5e97-9be4-563bfff7e529
Feed Name: Datadog Security Labs
Datadog Security Labs documents an active campaign where attackers (clustered on Indonesian residential-proxy IPs/ASNs) abused leaked AWS IAM credentials to create administrator users, enumerate and access resources (S3, EC2 via Instance Connect), and spin up hundreds of ECS Fargate clusters and thousands of containers across regions to run XMRig cryptocurrency miners using malicious Docker Hub images; the report provides indicators (image names, ASN, IP range), MITRE ATT&CK mappings, and detection/remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
