Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Customers of Amazon Web Services (AWS) have been the subject of an ongoing effort that uses compromised Identity and Access Management (IAM) credentials to facilitate cryptocurrency mining.
According to a new report released by the tech giant ahead of publication, the activity, which was initially discovered on November 2, 2025, by Amazon's GuardDuty managed threat detection service and its automated security monitoring systems, uses never-before-seen persistence techniques to impede incident response and continue unhindered.
Before deploying cryptocurrency mining resources across ECS and EC2, the threat actor swiftly listed resources and permissions while operating from an external hosting provider, according to Amazon. Crypto miners were up and running within ten minutes of the th...

