AMBERSQUID hides in the depths. [Research Saturday]

Published: Oct. 21, 2023, 7 a.m.

Sysdig's Alessandro Brucato and Michael Clark join Dave to discuss their work on "AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation." Attackers are targeting what are typically considered secure AWS services, like AWS Fargate and Amazon SageMaker. This means that defenders generally aren\u2019t as concerned with their security from end-to-end.\nThe research states "The AMBERSQUID operation was able to exploit cloud services without triggering the AWS requirement for approval of more resources, as would be the case if they only spammed EC2 instances." This poses additional challenges targeting multiple services since it requires finding and killing all miners in each exploited service.\nThe research can be found here:\nAWS\u2019s Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices