Security researchers are warning that Amazon Machine Images (AMIs) infected with malware could compromise an organization's cloud environment.
Although the method is not new, it could become a trend unless you take the proper precautions before deploying an Elastic Compute Cloud (EC2) based on “community AMIs”.

During a recent engagement at a financial institution, Mitiga researchers found that an EC2 server in the client's Amazon Web Services (AWS) environment was executing unauthorized code.
They discovered an active crypto miner that had not been deployed, exploiting a vulnerability or misconfiguration. Instead, it was embedded in the community that was using the AMI to create EC2.
AMIs are available through the AWS Marketplace from well-known vendors and the community. In this particular case, the infected image was for Microsoft Windows Server 2008 and came from an unknown provider.
Since the AMI was within the scope of Mitiga's assessment, the researchers identified the embedded miner that mined Monero.
Contrary to expectations, the creator of AMI did not use the popular XMRig miner but Claymore's GPU -powered CryptoNote .
Mitiga warns that while in this case only the account , cybercriminals could install code that could cause serious damage to a company.
The backdoors would allow a connection to the Windows, which could be used as a stepping stone to deeper “areas” of the environment, even “the entire EC2 infrastructure of the affected AWS account.”
Given these potential threats, the researchers recommend that AWS customers who choose community AMIs run them in a test environment and perform a security audit before launching them in a mission-critical environment.
Using AMIs from trusted sources (known vendors on the AWS Marketplace), although costly, will not create any problems, Mitiga concluded based on the results of further investigation of this incident.
"It's true that some Community AMIs can often be cost-conscious solutions, but these savings must be balanced against the risks posed by binaries whose origins and contents are suspicious at best, or completely unknown at worst," the researchers say in a blog post.
