Executive Summary
In November 2025, Amazon Web Services (AWS) identified a sophisticated cryptocurrency mining campaign targeting Amazon EC2 and Amazon ECS services. Threat actors utilized compromised AWS Identity and Access Management (IAM) credentials to deploy mining operations rapidly, often within minutes of gaining access. They employed advanced persistence techniques, such as modifying instance attributes to disable termination, complicating incident response efforts. This campaign underscores the critical importance of securing IAM credentials and monitoring for unauthorized activities within cloud environments.
The incident highlights a growing trend of attackers leveraging legitimate credentials to exploit cloud resources for illicit purposes. Organizations must prioritize robust access controls, implement multi-factor authentication, and continuously monitor for anomalous behaviors to mitigate such threats effectively.
Why This Matters Now
The rapid evolution of cloud-based attacks, exemplified by this cryptomining campaign, necessitates immediate attention to IAM security practices and real-time threat detection mechanisms to prevent unauthorized resource exploitation.
Attack Path Analysis
An attacker gained unauthorized access to an EC2 instance, escalated privileges by attaching an AdministratorAccess policy, moved laterally to deploy additional mining operations, established command and control through DNS queries to mining pools, exfiltrated data by sending mining results to external servers, and impacted the environment by consuming resources for cryptocurrency mining.
Kill Chain Progression
Initial Compromise
Description
An attacker gained unauthorized access to an EC2 instance, possibly through compromised IAM credentials.
MITRE ATT&CK® Techniques
Resource Hijacking: Compute Hijacking
Application Layer Protocol
Create or Modify System Process: Launch Agent
Command and Scripting Interpreter: Unix Shell
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing firewalls are documented, in use, and known to all affected parties.
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptomining threats expose cloud infrastructure vulnerabilities, requiring enhanced egress security controls and zero trust segmentation to protect sensitive financial data and prevent unauthorized resource usage.
Health Care / Life Sciences
Healthcare cloud environments face HIPAA compliance risks from cryptomining attacks that exploit encrypted traffic gaps and inadequate east-west segmentation, threatening patient data security and system integrity.
Government Administration
Government cloud infrastructure vulnerable to cryptomining exploits requiring immediate implementation of threat detection capabilities and multicloud visibility controls to prevent resource compromise and maintain operational security.
Computer Software/Engineering
Software companies managing AWS environments need enhanced Kubernetes security and cloud firewall capabilities to prevent cryptomining attacks that exploit container orchestration and development infrastructure vulnerabilities.
Sources
- Accelerate security investigations with Kiro CLIhttps://aws.amazon.com/blogs/security/accelerate-security-investigations-with-kiro-cli/Verified
- GuardDuty EC2 finding types - Amazon GuardDutyhttps://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.htmlVerified
- GuardDuty finding format - Amazon GuardDutyhttps://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-format.htmlVerified
- Understanding and generating Amazon GuardDuty findings - Amazon GuardDutyhttps://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be limited to the compromised instance, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, limiting their access to other resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be restricted, reducing the spread of malicious activities.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications would likely be detected and disrupted, limiting their ability to manage compromised instances.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be hindered, reducing the risk of data loss.
The attacker's impact on resource consumption and financial loss would likely be minimized, reducing overall damage.
Impact at a Glance
Affected Business Functions
- Cloud Infrastructure Management
- Compute Resource Operations
- Security Monitoring
Estimated downtime: 1 days
Estimated loss: $5,000
Potential exposure of compute resources to unauthorized cryptomining activities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement least privilege IAM policies to prevent unauthorized privilege escalation.
- • Enforce multi-factor authentication (MFA) for all users to protect against credential compromise.
- • Deploy network segmentation to limit lateral movement within the environment.
- • Monitor DNS traffic for unusual patterns indicative of command and control communications.
- • Establish automated alerting and response mechanisms to detect and mitigate unauthorized activities promptly.



