GuardDuty Extended Threat Detection uncovers cryptomining campaign on Amazon EC2 and Amazon ECS
ID: 400001eb-a8b0-5417-99fe-0194c70cbb3e
STIX ID: report--400001eb-a8b0-5417-99fe-0194c70cbb3e
Feed Name: AWS Security Blog
This GuardDuty report describes an active, large-scale crypto-mining campaign beginning November 2, 2025, in which attackers used compromised AWS IAM credentials to rapidly enumerate quotas and deploy mining workloads across EC2 and ECS/Fargate (including GPU instances), employed persistence techniques such as disabling API termination and creating public unauthenticated Lambda URLs, and distributed a malicious Docker image (yenik65958/secret) connecting to rplant.xyz mining pools; the advisory includes IoCs, detection methods (GuardDuty findings, Runtime Monitoring), and remediation and prevention recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
