Denonia Malware Targets Poorly Secured Lambda AWS Instances

Cybercriminals have unleashed a new malware family called Denonia. It engages in highly-targeted attacks, which go after a specific network – the Lambda AWS service. This service is associated with Amazon Web Services, and it is typically used by software developers all over the world. The Denonia Malware is written in the Go programming language, which has been gradually gaining popularity among malware developers.

The criminals behind the Denonia Malware are probably well-versed with the infrastructure of Lambda AWS in order to develop a threat that is able to exploit these services, and take control of them. Researchers report that it is not yet clear what the infection vector is that Denonia Malware's operators use to plant their malicious app on Lambda servers. However, they suspect that the criminals might be exploiting poorly-secured setups whose login credentials are easy to obtain, or subject to bruteforce attacks. This means that the Lambda AWS service is secure – it's the users that are failing to secure it properly.

But enough about deployment – what does the Denonia Malware do? It seems that it is currently being used to deploy Trojanized copies of the XMRig cryptocurrency miner. Basically, the cybercriminals are hijacking the hardware resources of vulnerable Lambda servers in order to mine for cryptocurrencies like Monero. Remember that any cloud services you use must always be protected as well as possible – cybercriminals are preying on them as well. Using strong security credentials is a surefire way to make sure that the Denonia Malware never reaches your Lambda AWS.

April 7, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.