Gemalto
Incident posture
Timeline
Summary
Hackers gained unauthorized access to Amazon Web Services infrastructure used by Aviva and Gemalto, hijacking their computing resources to mine Bitcoin cryptocurrency. The intrusion did not involve data theft or attempts to steal sensitive information, and the affected companies were notified by the security researchers who discovered the activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A group of hackers gained unauthorized access to Amazon Web Services infrastructure that was being used by two companies, Aviva and Gemalto. Once inside, the attackers did not attempt to exfiltrate sensitive data such as personal information or credentials. Instead, they repurposed the compromised compute instances to perform cryptocurrency mining for Bitcoin. The hackers’ activity consisted of running workloads that solved the mathematical puzzles required to generate new Bitcoin tokens.
The security research group RedLock identified the intrusion and published a report describing the compromised instances as having been turned into parasitic bots conducting nefarious activity on the internet. RedLock noted that the attackers’ focus on resource hijacking rather than data theft was unusual compared to typical breach motives. Following the discovery, RedLock notified Amazon, Aviva, and Gemalto about the compromise.
Amazon, Aviva, and Gemalto were all informed of the incident by RedLock at the time the article was written. None of the three companies had issued any public statements regarding the breach. The unauthorized consumption of compute power for mining resulted in the companies’ resources being used to generate cryptocurrency that benefited only the attackers.
Sources
Sources available to members: 1 source.