logo

GuardDuty Extended Threat Detection uncovers cryptomining campaign on Amazon EC2 and Amazon ECS

ID: 400001eb-a8b0-5417-99fe-0194c70cbb3e

STIX ID: report--400001eb-a8b0-5417-99fe-0194c70cbb3e

Feed Name: AWS Security Blog

Threat Score
75/100

Date Published: 2025-12-16

Date Updated: 2026-04-27

Author: Kyle Koeller

...
...

This GuardDuty report describes an active, large-scale crypto-mining campaign beginning November 2, 2025, in which attackers used compromised AWS IAM credentials to rapidly enumerate quotas and deploy mining workloads across EC2 and ECS/Fargate (including GPU instances), employed persistence techniques such as disabling API termination and creating public unauthenticated Lambda URLs, and distributed a malicious Docker image (yenik65958/secret) connecting to rplant.xyz mining pools; the advisory includes IoCs, detection methods (GuardDuty findings, Runtime Monitoring), and remediation and prevention recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.