AWS Systems Targeted by Crypto Mining Scam Using Hijacked IAM Credentials


  • The attackers used stolen high-privileged IAM credentials to rapidly deploy cryptomining at scale on EC2 and ECS.
  • They launched auto-scaling groups using a lot of GPUs, malicious Fargate containers, new IAM users, and shutdown-protected instances.
  • AWS recommends strict IAM hygiene: MFA everywhere, temporary credentials, and least privilege access

Cybercriminals are targeting Amazon Web Services (AWS) customers using Amazon EC2 and Amazon ECS with cryptojackers, experts have warned.

The cloud giant warned of the ongoing campaign in a recent report, saying it had since been resolved, but urged its customers to be careful as such attacks can easily resurface.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top