Novel Attack Vector to Abuse AWS for Cryptojacking
Nahfid Nissar, S Arjun, K. Sriram Siddartha, Shaik Muzamil Raheman · 2024
This study investigates cryptojacking attacks on cloud infrastructure, focusing on hacker groups and their methods from 2017 to 2024. We analyze how attackers deploy mining software and malware in the cloud, leading to performance degradation, resource consumption, and financial loss. Typically, these attacks target specific cloud resources like AWS EC2 or Lambda. Our novel approach involves using an EC2 instance as an internal command-and-control (C2) server to coordinate the provisioning of AWS ECS, Lightsail, and EKS services for mining purposes. System specifications are exfiltrated through DNS tunneling. We propose strategies and best practices for mitigating these attacks. Victims of these attacks often face significant costs, with each dollar gained by attackers resulting in nearly ${\$}$53 in electricity and compute bills.