GuardDuty Uncovers Ongoing Crypto Mining Campaign on Amazon EC2 and ECS
Amazon Web Services (AWS) has identified an ongoing cryptocurrency mining campaign using compromised IAM credentials to target Amazon Elastic Container Service (Amazon ECS) and Amazon Elastic Compute Cloud (Amazon EC2). GuardDuty Extended Threat Detection uncovered the operation, which began on November 2, 2025. The campaign employed a novel persistence technique designed to disrupt incident response … Read more