Learn languages naturally with fresh, real content!

tap to translate recording

Explore By Region

flag Hackers used stolen AWS credentials to secretly mine cryptocurrency, detected by AWS GuardDuty due to unusual behavior.

flag In November 2025, hackers used stolen AWS IAM credentials to secretly mine cryptocurrency on compromised cloud resources, deploying SBRMiner-MULTI malware on EC2 and ECS within minutes of gaining access. flag They avoided detection by testing with the RunInstances DryRun flag, disabled instance termination for persistence, created auto-scaling ECS clusters, and set up public Lambda functions for long-term access. flag AWS GuardDuty detected the activity via behavioral anomalies, prompting alerts to affected customers. flag The breach, linked to poor credential management like long-lived keys and missing MFA, underscores the risks of weak cloud security practices.

3 Articles