Suspicious activity

Anomaly detection: Role created new EC2 instances with miner from Tor IP address

Risk Level

Hazardous (3)



The role created ec2 instances in an amount which is unusual to its usage profile. It was found that at least one of those ec2 instances contains miner according to the bash history file. It is possible that the role was hijacked and used to create instances for malicious purposes in the environment, such as cryptomining. In addition, the api call was triggered from a tor ip address.
  • Recommended Mitigation

    It is recommended to review the actions of the role and remediate the infected instances. It is also recommended to check in the relevant CloudTrail events which entity used the role's permissions to create the infected instances.