Customers of Amazon Web Services (AWS) have been the subject of an ongoing effort that uses compromised Identity and Access Management (IAM) credentials to facilitate cryptocurrency mining.
According to a new report released by the tech giant ahead of publication, the activity, which was initially discovered on November 2, 2025, by Amazon’s GuardDuty managed threat detection service and its automated security monitoring systems, uses never-before-seen persistence techniques to impede incident response and continue unhindered.
Before deploying cryptocurrency mining resources across ECS and EC2, the threat actor swiftly listed resources and permissions while operating from an external hosting provider, according to Amazon. Crypto miners were up and running within ten minutes of the threat actor obtaining first access.
In essence, the multi-stage attack chain starts with an unknown adversary using compromised IAM user credentials with admin-like privileges to start a discovery phase intended read more about Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
