Detecting and preventing crypto mining in your AWS environment
Security Blog
This article explains how to detect and prevent cryptocurrency mining in AWS environments using Amazon GuardDuty and complementary security services.
- Crypto mining causes cost increases, performance degradation, and potential security incidents
- GuardDuty detects mining via DNS analysis, network communications, and runtime monitoring
- Specialized findings include CryptoCurrency:EC2/BitcoinTool.B and Impact:Runtime/CryptoMinerExecuted
- Enable GuardDuty across all accounts and regions with Runtime Monitoring activated
- Implement CloudWatch alarms for unusual CPU, network, and GPU usage spikes
- Deploy Network Firewall for outbound filtering to block mining infrastructure
- Use Systems Manager for patch management and security policy enforcement
- Enforce least privilege IAM access, MFA, and regular access key rotation
- AWS requires written approval for legitimate crypto mining activities
- Automated remediation via EventBridge and Lambda enables rapid incident response
A multi-layered defense combining GuardDuty detection, access controls, system maintenance, and automated responses provides comprehensive protection against unauthorized crypto mining.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.