HomeSecurityAmazon: Cryptomining campaign uses compromised AWS accounts

Amazon: Cryptomining campaign uses compromised AWS accounts

Amazon ’s AWS GuardDuty security team is warning of an ongoing cryptomining campaign targeting Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised Identity and Access Management (IAM) credentials . The operation began on November 2 and used a mechanism persistence that extended mining operations and thwarted network defenders. 

cryptomining Amazon

The threat actor used a Docker Hub image created in late October that had more than 100,000 downloads. Amazon EC2 allows users to run virtual machines on AWS, while ECS allows running containerized applications (e.g., Docker applications) on the cloud platform.

See also: GhostPoster malware found in 17 Firefox add-ons

Amazon: Dangerous cryptomining campaign

Installing crypto-miners in these cases allows threat actors to profit financially at the expense of AWS and Amazon customers, who must bear the burden of computing resource depletion. Amazon says the attacker did not exploit a vulnerability, but used valid credentials on customer accounts. AWS said the attacker began cryptomining within 10 minutes of initial access, after reconnaissance of EC2 service quotas and IAM permissions.

This was possible by registering a task definition shown in the Docker Hub image yenik65958/secret, created on October 29. This included an SBRMiner-MULTI cryptominer and a startup script to automatically start it when the container was started. Each task was configured with 16,384 CPU units and 32GB of memory, and the desired number of ECS Fargate tasks was set to 10.

See also: Android malware Cellik creates malicious versions of Google Play apps

Amazon: Cryptomining campaign uses compromised AWS accounts

On Amazon EC2, the attacker created two launch templates with startup scripts that automatically enabled cryptomining, along with 14 auto-scaling groups configured to deploy at least 20 instances each, with a maximum capacity of up to 999 machines. Once the machines were running, the attacker enabled a setting that prevented administrators from shutting them down remotely, forcing responders to explicitly disable protection before shutting them down.

This was likely introduced to delay response and maximize profits from cryptomining.

“An interesting technique observed in this campaign was the threat actor on all EC2 instances to disable API termination,” Amazon explains. “While instance termination protection prevents accidental termination, it adds an additional consideration for incident response capabilities and can disrupt automated remediation checks,” the company says.

See also: Amazon reveals multi-year GRU cyber campaign

Amazon: Cryptomining campaign uses compromised AWS accounts

After identifying the campaign, Amazon notified affected customers about the cryptocurrency mining and the need to change their compromised IAM credentials. The malicious Docker Hub image has been removed from the platform, but Amazon warns that the threat actor could deploy similar images with different names and publisher accounts.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS