Compromised IAM credentials drive AWS crypto mining campaign

Amazon has identified a new cryptocurrency mining operation on its AWS platform. The campaign exploits stolen IAM credentials and abuses services like ECS and EC2. Attackers use termination protection to maintain persistence.

Amazon Web Services (AWS) has disclosed details of a significant cryptocurrency mining campaign targeting its infrastructure. The operation relies on compromised Identity and Access Management (IAM) credentials to gain unauthorized access. Once inside, attackers deploy mining activities using Elastic Container Service (ECS) and Elastic Compute Cloud (EC2) instances.

To ensure longevity, the malicious actors enable termination protection on the compromised instances, preventing easy shutdowns. This persistence mechanism allows the mining to continue undetected for extended periods. AWS emphasizes that such abuses highlight the importance of securing IAM credentials to protect cloud environments.

The campaign represents a growing trend in cryptojacking, where unauthorized computing resources are hijacked for mining digital currencies. Organizations using AWS are advised to monitor for unusual activity in their IAM policies and instance configurations. No specific timeline or victim details were provided in the report, but the incident underscores ongoing cybersecurity challenges in cloud computing.

Labaran da ke da alaƙa

Three Amazon engineers testifying at a Seattle city council hearing against AI data center plans, with climate justice signs visible.
Hoton da AI ya samar

Amazon investigates three engineers over AI data center testimony

An Ruwaito ta hanyar AI Hoton da AI ya samar

Amazon is investigating three engineers who testified against the company's AI data center expansion plans at Seattle city council hearings. The employees, members of Amazon Employees for Climate Justice, face potential disciplinary action after urging stricter regulations on data centers.

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

An Ruwaito ta hanyar AI

Meta has quietly finalized a large-scale agreement with Amazon Web Services to rent its AI infrastructure, moving away from owning chips and expanding its own data centers. The deal marks an unprecedented shift to relying on AWS's backbone for AI needs.

Wannan shafin yana amfani da cookies

Muna amfani da cookies don nazari don inganta shafin mu. Karanta manufar sirri mu don ƙarin bayani.
Ƙi