By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Tech News

Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

By Viral Trending Content 5 Min Read
Share
SHARE

Dec 16, 2025Ravie LakshmananMalware / Threat Detection

An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining.

The activity, first detected by Amazon’s GuardDuty managed threat detection service and its automated security monitoring systems on November 2, 2025, employs never-before-seen persistence techniques to hamper incident response and continue unimpeded, according to a new report shared by the tech giant ahead of publication.

“Operating from an external hosting provider, the threat actor quickly enumerated resources and permissions before deploying crypto mining resources across ECS and EC2,” Amazon said. “Within 10 minutes of the threat actor gaining initial access, crypto miners were operational.”

The multi-stage attack chain essentially begins with the unknown adversary leveraging compromised IAM user credentials with admin-like privileges to initiate a discovery phase designed to probe the environment for EC2 service quotas and test their permissions by invoking the RunInstances API with the “DryRun” flag set.

This enabling of the “DryRun” flag is crucial and intentional as it enables the attackers to validate their IAM permissions without actually launching instances, thereby avoiding racking up costs and minimizing their forensic trail. The end goal of the step is to determine if the target infrastructure is suitable for deploying the miner program.

Cybersecurity

The infection proceeds to the next stage when the threat actor calls CreateServiceLinkedRole and CreateRole to create IAM roles for autoscaling groups and AWS Lambda, respectively. Once the roles are created, the “AWSLambdaBasicExecutionRole” policy is attached to the Lambda role.

In the activity observed to date, the threat actor is said to have created dozens of ECS clusters across the environment, in some cases exceeding 50 ECS clusters in a single attack.

“They then called RegisterTaskDefinition with a malicious DockerHub image yenik65958/secret:user,” Amazon said. “With the same string used for the cluster creation, the actor then created a service, using the task definition to initiate crypto mining on ECS Fargate nodes.”

The DockerHub image, which has since been taken down, is configured to run a shell script as soon as it’s deployed to launch cryptocurrency mining using the RandomVIREL mining algorithm. Additionally, the threat actor has been observed creating autoscaling groups that are set to scale from 20 to 999 instances in an effort to exploit EC2 service quotas and maximize resource consumption.

The EC2 activity has targeted both high-performance GPU and machine learning instances and compute, memory, and general-purpose instances.

What makes this campaign stand apart is its use of the ModifyInstanceAttribute action with the “disableApiTermination” parameter set to “True,” which prevents an instance from being terminated using the Amazon EC2 console, command line interface, or API. This, in turn, has the effect of requiring victims to re-enable API termination before deleting the impacted resources.

“Instance termination protection can impair incident response capabilities and disrupt automated remediation controls,” Amazon said. “This technique demonstrates an understanding of common security response procedures and intent to maximize the duration of mining operations.”

This is not the first time the security risk associated with ModifyInstanceAttribute has come to light. In April 2024, security researcher Harsha Koushik demonstrated a proof-of-concept (PoC) that detailed how the action can be abused to take over instances, exfiltrate instance role credentials, and even seize control of the entire AWS account.

Furthermore, the attacks entail the creation of a Lambda function that can be invoked by any principal and an IAM user “user-x1x2x3x4” to which the AWS managed policy “AmazonSESFullAccess” is attached, granting the adversary complete access over the Amazon Simple Email Service (SES) to likely carry out phishing attacks.

Cybersecurity

To secure against the threat, Amazon is urging AWS customers to follow the steps below –

  • Enforce strong identity and access management controls
  • Implement temporary credentials instead of long-term access keys
  • Use multi-factor authentication (MFA) for all users
  • Apply the principle of least privilege (PoLP) to IAM principals to restrict access
  • Add container security controls to scan for suspicious images
  • Monitor unusual CPU allocation requests in ECS task definitions
  • Use AWS CloudTrail to log events across AWS services
  • Ensure AWS GuardDuty is enabled to facilitate automated response workflows

“The threat actor’s scripted use of multiple compute services, in combination with emerging persistence techniques, represents a significant advancement in crypto mining attack methodologies.”

You Might Also Like

iPhone 17e: Price, Release Date, Specs and Features

Pumped Hydro Energy Storage Is Having a Renaissance

New report early stage state supports for Irish tech sector

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

GPT-5.2 vs Gemini 3 Comparison : Strengths, Weaknesses & Best Use Cases

TAGGED: Amazon Web Services, Cloud Infrastructure, Cloud security, Container Security, Cryptomining, Cyber Security, Cybersecurity, Incident response, Internet, Malware, threat detection
Share This Article
Facebook Twitter Copy Link
Previous Article New to investing in the stock market? Here’s how to try to beat the Martin Lewis method!
Next Article Entertainment IP Summit 2026 Announces Keynote with Best-Selling Author Eoin Colfer as Part of Global Exploration of Cross-Platform Storytelling and IP Strategy
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Who are the Westerners sanctioned by the EU for spreading Russian propaganda?
World News
Sky Sports to remain home of The Masters in new multi-year extension
Sports
TIAA financial services firm to move from downtown Denver into smaller Glendale office
Business
China's Clean Energy Push is Powering Flying Taxis, Food Delivery Drones and Bullet Trains
World News
Starfield Improvements Were Showcased in a Closed-Door Event for Version 2.0 – Rumour
Gaming News
Uniswap price gains amid potential 100M UNI burn
Crypto
Down over 30% this year, could these 3 UK shares bounce back in 2026?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Who are the Westerners sanctioned by the EU for spreading Russian propaganda?

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Who are the Westerners sanctioned by the EU for spreading Russian propaganda?
December 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?