New cryptojacking attacks target uncommon AWS instances
Cybersecurity researchers from Sysdig recently uncovered a new cryptojacking campaign that targeted uncommon Amazon Web Services (AWS) services.
Cryptojacking is a type of cyberattack in which the threat actor secretly installs a cryptocurrency miner on a target endpoint. While not malicious per se, miners bring profit to their owners, while the victims are left with inflated electricity and data bills, and a virtually unusable device (until the cryptojacker is removed). There are multiple uncommon AWS services, including AWS Amplify, AWS Fargate, and Amazon SageMaker, that were targeted here.
This campaign was dubbed AMBERSQUID. “The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances,” said Alessandro Brucato, Sysdig security researcher.
AMBERSQUID attacks
“Targeting multiple services also poses additional challenges, like incident response, since it requires finding and killing all miners in each exploited service,” the researchers added.
Further investigation found that the attackers were mostly likely of Indonesian origin, as some of the scripts and usernames were written in the Indonesian language. By analyzing blockchain data associated with the cryptominers, the researchers were able to determine that the attackers generated at least $18,000 in profits. On the other hand, they estimate that AMBERSQUID could cost more than $10,000 a day, if it were scaled to target all AWS regions.
Cryptojacking has been around for as long as cryptocurrency itself. Earlier this year, Microsoft found hackers brute-forcing their way into Linux-based IoT devices, and using them to mine cryptocurrencies. They even made sure that no rival cryptojackers were installed on the vulnerable endpoints.
By far the most popular cryptojacking software is XMRig, a miner that generates a token known as Monero, or XMR. This is a token with a strong emphasis on privacy, with some arguing that it’s absolutely untraceable.
More from TechRadar Pro
Cybersecurity researchers from Sysdig recently uncovered a new cryptojacking campaign that targeted uncommon Amazon Web Services (AWS) services. Cryptojacking is a type of cyberattack in which the threat actor secretly installs a cryptocurrency miner on a target endpoint. While not malicious per se, miners bring profit to their owners, while…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023