The Containment Era is here. →Explore

Executive Summary

In late 2025, Amazon's AWS GuardDuty team uncovered a significant cryptomining campaign that exploited compromised IAM credentials to gain access to AWS Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) environments. The attackers used valid credentials, rather than technical vulnerabilities, to deploy a malicious Docker Hub image carrying an SBRMiner-MULTI cryptominer. By rapidly launching large-scale EC2 and ECS tasks with high compute and memory allocations, the threat actor inflicted resource exhaustion and financial losses upon AWS customers. Attackers also enabled termination protection on compromised instances, effectively delaying incident response and extending mining profits.

This incident is emblematic of the growing sophistication and automation in cloud resource abuse, highlighting an uptick in attacks leveraging stolen credentials rather than software flaws. As cloud adoption surges and cryptomining threats evolve, organizations face urgent pressure to enhance IAM hygiene, monitoring, and automated remediation to reduce risk.

Why This Matters Now

This breach underscores the increasing threat posed by identity-driven attacks in cloud environments, as attackers exploit valid credentials to bypass traditional security controls. New persistence techniques and rapid deployment of resource-intensive workloads make timely detection, robust IAM governance, and automated response essential to prevent costly cloud exploitation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers obtained compromised IAM credentials, which allowed them to deploy cryptomining containers and large-scale EC2 resources without exploiting technical vulnerabilities.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west traffic controls, egress policy enforcement, network visibility, and microsegmentation would have confined the attack, detected abnormal instance proliferation, and blocked outbound mining activity. CNSF controls aligned with least-privilege access and continuous threat monitoring would have minimized the blast radius and enabled faster remediation.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Anomalous account logins and management activity would be detected rapidly.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Unnecessary access paths and privilege escalation would be blocked.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Movement between workloads, regions, or environments would be limited or prevented.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outgoing mining traffic to unauthorized domains/IPs would be detected and blocked.

Exfiltration

Control: Cloud Firewall (ACF)

Mitigation: Data and traffic egress to unapproved destinations would be blocked.

Impact (Mitigations)

Rapid detection of abnormal auto-scaling, resource spikes, and blocked termination actions.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Financial Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

No evidence of data exposure; the primary impact was unauthorized resource consumption leading to increased operational costs.

Recommended Actions

  • Immediately implement Zero Trust segmentation and least-privilege policies for all IAM users and services.
  • Enforce east-west and egress traffic controls, including application-layer FQDN filtering and cloud firewalling, to block unauthorized network flows.
  • Continuously monitor cloud management activity and resource deployment for anomaly-based alerts and automated remediation triggers.
  • Regularly rotate and audit IAM credentials, and restrict use of privileged roles through granular access control and segmentation.
  • Deploy real-time threat detection and network observability to rapidly identify and contain suspicious resource or network activity across cloud environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image