New cryptojacking attacks target uncommon AWS instances

Bitcoin mining
(Image credit: Pixabay)

Cybersecurity researchers from Sysdig recently uncovered a new cryptojacking campaign that targeted uncommon Amazon Web Services (AWS) services.

Cryptojacking is a type of cyberattack in which the threat actor secretly installs a cryptocurrency miner on a target endpoint. While not malicious per se, miners bring profit to their owners, while the victims are left with inflated electricity and data bills, and a virtually unusable device (until the cryptojacker is removed). There are multiple uncommon AWS services, including AWS Amplify, AWS Fargate, and Amazon SageMaker, that were targeted here.

This campaign was dubbed AMBERSQUID. "The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances," said Alessandro Brucato, Sysdig security researcher.

AMBERSQUID attacks

"Targeting multiple services also poses additional challenges, like incident response, since it requires finding and killing all miners in each exploited service," the researchers added. 

Further investigation found that the attackers were mostly likely of Indonesian origin, as some of the scripts and usernames were written in the Indonesian language. By analyzing blockchain data associated with the cryptominers, the researchers were able to determine that the attackers generated at least $18,000 in profits. On the other hand, they estimate that AMBERSQUID could cost more than $10,000 a day, if it were scaled to target all AWS regions. 

Cryptojacking has been around for as long as cryptocurrency itself. Earlier this year, Microsoft found hackers brute-forcing their way into Linux-based IoT devices, and using them to mine cryptocurrencies. They even made sure that no rival cryptojackers were installed on the vulnerable endpoints. 

By far the most popular cryptojacking software is XMRig, a miner that generates a token known as Monero, or XMR. This is a token with a strong emphasis on privacy, with some arguing that it’s absolutely untraceable.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does