Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
ID: bd6316bb-38ea-5c66-a5f3-a91274320c52
STIX ID: report--bd6316bb-38ea-5c66-a5f3-a91274320c52
Feed Name: Bleeping Computer
Threat Score
Amazon GuardDuty identified an ongoing cryptomining campaign that used compromised IAM credentials to deploy a Docker image (yenik65958/secret containing SBRMiner-MULTI) to EC2 and ECS resources. The attacker rapidly launched heavy-resource ECS tasks and EC2 auto-scaling groups and used ModifyInstanceAttribute to disable API termination for persistence; Amazon removed the malicious image and alerted affected customers to rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
