Cryptomining campaign targeting Amazon EC2 and Amazon ECS
Security Blog
This article details an ongoing cryptocurrency mining campaign targeting AWS EC2 and ECS using compromised IAM credentials, identified by GuardDuty starting November 2, 2025.
- Attackers used compromised IAM credentials to deploy crypto miners across EC2 and ECS within 10 minutes
- Malicious Docker image yenik65958/secret deployed SBRMiner-MULTI to containerized environments
- Novel persistence technique: ModifyInstanceAttribute disabled API termination to complicate incident response
- Attackers created 50+ ECS clusters and 14 auto scaling groups with aggressive scaling (max 999 instances)
- DryRun API calls used for reconnaissance to validate permissions without launching instances
- Lambda function created with public endpoint (AuthType: NONE) for potential persistence
- GuardDuty Extended Threat Detection correlated signals as AttackSequence:EC2/CompromisedInstanceGroup
- Crypto mining domains: asia.rplant.xyz, eu.rplant.xyz, na.rplant.xyz
- Recommendations: enforce MFA, use temporary credentials, enable GuardDuty Runtime Monitoring, implement SCPs denying public Lambda URLs
AWS recommends prioritizing identity controls, enabling GuardDuty across all accounts/regions, and establishing incident response procedures for crypto mining attacks.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.