Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries
Retrospective: this article looks back at events from February 2018, written in 2026 with the benefit of hindsight.
Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most detectable, if you know where to look.
Signals worth watching
- New EC2 instances, especially GPU or large compute types, in regions you don't use.
- Sudden increases in vCPU usage or service quota increase requests.
- Instances or containers connecting to mining pools or to unfamiliar endpoints on unusual ports.
- New IAM users, access keys or roles created shortly before compute spikes.
- Unexpected cost anomalies.
Where the data lives
- GuardDuty: findings such as
CryptoCurrency:EC2/BitcoinTooland runtime findings for containers. - CloudTrail:
RunInstances,CreateUser,CreateAccessKeyand quota requests. - AWS Cost Anomaly Detection and budgets.
- VPC Flow Logs for outbound connections.
A starting query
Look for instance launches in regions your organization doesn't normally use:
AWSCloudTrail
| where EventName == "RunInstances" and isempty(ErrorCode)
| summarize Launches = count() by AWSRegion, UserIdentityArn, bin(TimeGenerated, 1h)
| where AWSRegion !in ("us-east-1", "us-west-2")
Replace the region list with your approved regions.
Prevention plus detection
An SCP that denies activity outside approved regions removes much of the problem. Cost anomaly alerts act as a backstop.
Response
- Terminate the mining instances after snapshotting one for investigation.
- Identify and disable the credentials used.
- Check for other persistence the attacker created.
- Request a billing review from AWS if charges are significant.