logo

Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

ID: bd6316bb-38ea-5c66-a5f3-a91274320c52

STIX ID: report--bd6316bb-38ea-5c66-a5f3-a91274320c52

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Amazon GuardDuty identified an ongoing cryptomining campaign that used compromised IAM credentials to deploy a Docker image (yenik65958/secret containing SBRMiner-MULTI) to EC2 and ECS resources. The attacker rapidly launched heavy-resource ECS tasks and EC2 auto-scaling groups and used ModifyInstanceAttribute to disable API termination for persistence; Amazon removed the malicious image and alerted affected customers to rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.