Scworld
AWS IAM Credential Theft Fuels Ongoing Crypto Mining Campaign
First seen 17 Dec 2025, 22:54 UTC
•


•27.0
Export
Article Content
Browse articles
A sophisticated cryptocurrency mining campaign targeting AWS customers began on November 2, 2025, using compromised AWS Identity and Access Management (IAM) credentials. The attackers exploited Amazon Elastic Container Service (ECS) and Elastic Compute Cloud (EC2) and employed advanced persistence techniques to extend their operations and evade detection. Amazon's GuardDuty detected the attack and raised a critical severity alert.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon Q Developer Vulnerability Enables Cloud Credential Theft
Data Centers Targeted Amid Rising Cybersecurity Threats
Iran Targets Data Centers Amid Rising Cyber Warfare Tensions