AWSDetection & ResponseRetrospectives

Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2018, written in 2026 with the benefit of hindsight.

Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most detectable, if you know where to look.

Signals worth watching

  • New EC2 instances, especially GPU or large compute types, in regions you don't use.
  • Sudden increases in vCPU usage or service quota increase requests.
  • Instances or containers connecting to mining pools or to unfamiliar endpoints on unusual ports.
  • New IAM users, access keys or roles created shortly before compute spikes.
  • Unexpected cost anomalies.

Where the data lives

  • GuardDuty: findings such as CryptoCurrency:EC2/BitcoinTool and runtime findings for containers.
  • CloudTrail: RunInstances, CreateUser, CreateAccessKey and quota requests.
  • AWS Cost Anomaly Detection and budgets.
  • VPC Flow Logs for outbound connections.

A starting query

Look for instance launches in regions your organization doesn't normally use:

AWSCloudTrail
| where EventName == "RunInstances" and isempty(ErrorCode)
| summarize Launches = count() by AWSRegion, UserIdentityArn, bin(TimeGenerated, 1h)
| where AWSRegion !in ("us-east-1", "us-west-2")

Replace the region list with your approved regions.

Prevention plus detection

An SCP that denies activity outside approved regions removes much of the problem. Cost anomaly alerts act as a backstop.

Response

  1. Terminate the mining instances after snapshotting one for investigation.
  2. Identify and disable the credentials used.
  3. Check for other persistence the attacker created.
  4. Request a billing review from AWS if charges are significant.
detect cryptojacking in cloudTesla cryptojacking2018

More on this story