AWS Systems Hit by Crypto Mining Scam Using Hijacked IAM Credentials



  • Attackers used stolen high-privilege IAM credentials to rapidly deploy large-scale crypto mining on EC2 and ECS
  • They launched GPU-heavy auto-scaling groups, malicious Fargate containers, new IAM users, and instances protected from shutdown.
  • AWS urges strict IAM hygiene: MFA everywhere, temporary credentials, and least privileged access

Experts have warned that cybercriminals are targeting Amazon Web Services (AWS) customers using Amazon EC2 and Amazon ECS with cryptojackers.

The cloud giant warned about the ongoing campaign in a recent report, saying it has already been addressed, but urged customers to be careful because attacks like these can easily reappear.



Leave a Comment

Your email address will not be published. Required fields are marked *