• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

EleKtra-Leak Campaign Uses AWS Cloud Keys Found on Public GitHub Repositories to Run Cryptomining Operation

3 November 2023
in Mining
Reading Time: 7 mins read
A A
0
EleKtra-Leak Campaign Uses AWS Cloud Keys Found on Public GitHub Repositories to Run Cryptomining Operation
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

In the active Elektra-Leak campaign, attackers hunt for Amazon IAM credentials within public GitHub repositories before using them for cryptomining. Get tips on mitigating this cybersecurity threat.

Image: WhataWin

New research from Palo Alto Networks’s Unit 42 exposes an active attack campaign in which a threat actor hunts for Amazon IAM credentials in real time in GitHub repositories and starts using them less than five minutes later. The final payload runs customized Monero cryptomining software on virtual machines deployed on the Amazon instances.

Jump to:

IAM credentials exposed on GitHub

GitHub offers its users many features for handling their code within the platform. One of these features consists of providing a list of all public repositories to any user requesting it, which helps developers easily track various developments they are interested in. The tracking is done in real time and allows anyone, including threat actors, to see new repositories as soon as they are being pushed to GitHub.

SEE: 8 Best Identity and Access Management (IAM) Solutions for 2023 (TechRepublic)

Palo Alto Networks’s Unit 42 researchers report that it is possible to find Amazon Web Services Identity and Access Management credentials within GitHub’s public repositories and that these credentials are actively hunted for by cybercriminals.

To analyze the risk deeper, the researchers decided to store IAM credentials on GitHub and check all activity around it. That honeypot testing revealed that leaked AWS keys that were encoded in base64 and stored on GitHub were not found or used by threat actors, who only fetched clear text AWS keys hidden behind a past commit in a random file.

The honeypot enabled researchers William Gamazo and Nathaniel Quist to detect a particular attack campaign starting within five minutes after the credentials were put on GitHub.

Technical details about this attack campaign

The campaign, dubbed EleKtra-Leak by the researchers in reference to the Greek cloud nymph Electra and the usage of Lek as the first 3 characters in the passwords used by the threat actor, has been active since at least December 2020, according to Unit 42.

Once IAM credentials are found, the attacker performs a series of reconnaissance actions to know more about the AWS account that is accessed (Figure A).

Figure A

Reconnaissance actions run by the threat actor on the AWS account.
Reconnaissance actions run by the threat actor on the AWS account. Image: Palo Alto Networks

After those actions are done, the threat actor creates new AWS Security Groups before launching multiple Amazon Elastic Compute Cloud instances per region across any accessible AWS region.

Gamazo and Quist could observe more than 400 API calls within seven minutes, all done via a VPN connection, showing that the actor has automated the attack against those AWS account environments.

Must-read security coverage

The threat actor aimed at large-format cloud virtual machines to perform their operations, as those have higher processing power, which is what attackers are looking for when running cryptomining operations. The threat actor also chose private images for Amazon Machine Images; some of those images were old Linux Ubuntu distributions, leading the researchers to believe the operation dates back to at least 2020.

The threat actor also appeared to block AWS accounts that routinely expose IAM credentials, as this kind of behavior might originate from threat researchers or honeypot systems.

The goal of this attack campaign: Cryptomining

Once all the reconnaissance is done and virtual machines are launched, a payload is being delivered, downloaded from Google Drive. The payload, encrypted on Google storage, is being decrypted upon download.

Unit 42 states the payload is a known cryptomining tool seemingly used in 2021 and reported by Intezer, a company specializing in autonomous Security Operation Systems platforms. In the reported attack campaign, Intezer indicated that a threat actor had accessed exposed Docker instances on the internet to install cryptomining software for mining Monero cryptocurrency. That customized cryptomining software is the same as what is used in the new campaign exposed by Palo Alto Networks.

The software is configured to use the SupportXMR mining pool. Mining pools allow several people to add their computing time to the same workspace, increasing their chances to earn more cryptocurrency. As stated by Palo Alto Networks, the SupportXMR service only provides time-limited statistics, so the researchers pulled the mining statistics for several weeks, as the same wallet was used for the AWS mining operations (Figure B).

Figure B

SupportXMR statistics associated with the threat actor’s wallet.
SupportXMR statistics associated with the threat actor’s wallet. Image: Palo Alto Networks

Between Aug. 30, 2023 and Oct. 6, 2023, a total of 474 unique miners appeared, each one being a unique Amazon EC2 instance. It is not yet possible to obtain an estimation of the financial gain generated by the threat actor, as Monero includes privacy controls limiting the tracking of this kind of data.

GitHub’s automated measures for detecting secrets

GitHub automatically scans for secrets in files stored on the platform and notifies service providers about leaked secrets on GitHub.

During their investigation, Gamazo and Quist noticed the secrets they were intentionally storing on GitHub as honeypot data for their research were indeed successfully detected by GitHub and reported to Amazon, who in turn automatically applied within minutes a quarantine policy that prevents attackers from performing operations such as accessing AWS IAM, EC2, S3, Lambda and Lightsail.

During the research process, Unit 42 was leaving the quarantine policy in place and passively studying the attackers’ tests of the accounts; then, the policy was dropped to study the entire attack chain.

The researchers write that they “believe the threat actor might be able to find exposed AWS keys that aren’t automatically detected” and that according to their evidence, the attackers likely did, as they could operate the attack without any interfering policy. They also state that “even when GitHub and AWS are coordinated to implement a certain level of protection when AWS keys are leaked, not all cases are covered,” and that other potential victims of this threat actor might have been targeted in a different manner.

How to mitigate this cybersecurity risk

IAM credentials should never be stored on GitHub or any other online service or storage. Exposed IAM credentials should be removed from repositories, and new IAM credentials should be generated to replace the leaked ones.

Businesses should use short-lived credentials for performing any dynamic functionality within a production environment.

Security teams should monitor GitHub repositories used by their organizations. Auditing clone events that occur on those repositories should be done because it is necessary for threat actors to first clone repositories to view their content. That feature is available for all GitHub Enterprise accounts.

Custom dedicated scanning for secrets on repositories should also be done constantly. Tools such as Trufflehog might help with that task.

If there is no need to share the organization’s repositories publicly, private GitHub repositories should be used and only accessed by the organization’s personnel. Access to the private GitHub repositories should be protected by multifactor authentication to avoid an attacker accessing them with leaked login credentials.

Disclosure: I work for Trend Micro, but the views expressed in this article are mine.

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AWScampaignCloudCryptoMiningEleKtraLeakGitHubKeysoperationPublicRepositoriesRun
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Multichain inside job? And SOL surges 80% in a month: Finance Redefined

Next Post

Crypto Trader Updates Dogecoin and Solana Outlook, Sees ‘Moment of Truth’ for Bitcoin Layer-2 Project

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Crypto Trader Updates Dogecoin and Solana Outlook, Sees ‘Moment of Truth’ for Bitcoin Layer-2 Project

Crypto Trader Updates Dogecoin and Solana Outlook, Sees ‘Moment of Truth’ for Bitcoin Layer-2 Project

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
What It Means for BTC Price Action

What It Means for BTC Price Action

12 September 2025
Why Investors Should Pay Attention to These 3 Crypto Narratives

Why Investors Should Pay Attention to These 3 Crypto Narratives

12 September 2025
[LIVE] Crypto News Today, September 12 – Bitcoin Crosses $115K, SOL Price Surges To $238 And BNB Hits A New ATH: Best Crypto To Buy Now? – 99Bitcoins

[LIVE] Crypto News Today, September 12 – Bitcoin Crosses $115K, SOL Price Surges To $238 And BNB Hits A New ATH: Best Crypto To Buy Now? – 99Bitcoins

12 September 2025
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • What It Means for BTC Price Action
  • Why Investors Should Pay Attention to These 3 Crypto Narratives
  • [LIVE] Crypto News Today, September 12 – Bitcoin Crosses $115K, SOL Price Surges To $238 And BNB Hits A New ATH: Best Crypto To Buy Now? – 99Bitcoins
  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 114,961.00
  • ethereumEthereum (ETH) $ 4,515.39
  • xrpXRP (XRP) $ 3.04
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 238.96
  • bnbBNB (BNB) $ 907.01
  • usd-coinUSDC (USDC) $ 0.999803
  • dogecoinDogecoin (DOGE) $ 0.260209
  • staked-etherLido Staked Ether (STETH) $ 4,508.22
  • tronTRON (TRX) $ 0.348499
  • cardanoCardano (ADA) $ 0.891876
  • wrapped-stethWrapped stETH (WSTETH) $ 5,471.92
  • chainlinkChainlink (LINK) $ 24.38
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,866.76
  • hyperliquidHyperliquid (HYPE) $ 56.45
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,837.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.62
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.393044
  • wrapped-eethWrapped eETH (WEETH) $ 4,853.24
  • avalanche-2Avalanche (AVAX) $ 28.43
  • bitcoin-cashBitcoin Cash (BCH) $ 592.81
  • wethWETH (WETH) $ 4,515.14
  • hedera-hashgraphHedera (HBAR) $ 0.240841
  • leo-tokenLEO Token (LEO) $ 9.56
  • litecoinLitecoin (LTC) $ 115.54
  • crypto-com-chainCronos (CRO) $ 0.255232
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999288
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999942
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 114,992.00
  • polkadotPolkadot (DOT) $ 4.20
  • whitebitWhiteBIT Coin (WBT) $ 43.70
  • uniswapUniswap (UNI) $ 10.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199799
  • ethenaEthena (ENA) $ 0.761628
  • mantleMantle (MNT) $ 1.60
  • moneroMonero (XMR) $ 278.97
  • aaveAave (AAVE) $ 313.85
  • bitget-tokenBitget Token (BGB) $ 4.92
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 191.54
  • memecoreMemeCore (M) $ 2.18
  • jito-staked-solJito Staked SOL (JITOSOL) $ 293.74
  • ondo-financeOndo (ONDO) $ 1.08
  • myx-financeMYX Finance (MYX) $ 17.72