Suspicious activity

Aws Role suspicious behavior: Role created ec2 instances with malware

Risk Level

Imminent Compromised (2)

Platform(s)

Description

A role created ec2 instances in an amount which is unusual to its usage profile. It was found that few of those ec2 instances contain malwares. It is possible that the role was hijacked and used to create instances for malicious purposes in the environment, cryptomining for example.
  • Recommended Mitigation

    It is recommended to review the actions of the role and remediate the infected instances. It is also recommended to check in the relevant CloudTrail events which entity used the role permissions to create the infected instances.