AWS systems targeted by crypto mining scam using hijacked IAM credentials


  • Attackers used stolen high-privilege IAM credentials to rapidly deploy large-scale cryptomining on EC2 and ECS
  • They launched GPU-heavy auto-scaling groups, malicious Fargate containers, new IAM users and protected instances from shutdown
  • AWS encourages strict IAM hygiene: MFA everywhere, temporary credentials, and least-privileged access

Cybercriminals are targeting Amazon Web Services (AWS) customers using Amazon EC2 and Amazon ECS with cryptojackers, experts have warned.

The cloud giant warned about the ongoing campaign in a recent report and said it has since been patched, but urged customers to be cautious because attacks like these could easily re-emerge.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top