Learn languages naturally with fresh, real content!

Popular Topics
Explore By Region
Hackers used stolen AWS credentials to secretly mine cryptocurrency, detected by AWS GuardDuty due to unusual behavior.
In November 2025, hackers used stolen AWS IAM credentials to secretly mine cryptocurrency on compromised cloud resources, deploying SBRMiner-MULTI malware on EC2 and ECS within minutes of gaining access.
They avoided detection by testing with the RunInstances DryRun flag, disabled instance termination for persistence, created auto-scaling ECS clusters, and set up public Lambda functions for long-term access.
AWS GuardDuty detected the activity via behavioral anomalies, prompting alerts to affected customers.
The breach, linked to poor credential management like long-lived keys and missing MFA, underscores the risks of weak cloud security practices.
Los piratas informáticos utilizaron credenciales robadas de AWS para extraer criptomonedas en secreto, detectadas por AWS GuardDuty debido a un comportamiento inusual.