SBRMiner-MULTI is a cryptocurrency miner observed in an AWS-focused cryptomining campaign that abused stolen, valid IAM credentials with admin-like privileges rather than exploiting a software vulnerability. In the reported activity, attackers deployed SBRMiner-MULTI to both Amazon ECS and EC2 and were able to begin mining within about 10 minutes of initial access. Delivery included a malicious Docker Hub image, yenik65958/secret, created on October 29, 2025, which contained a SBRMiner-MULTI binary and a startup script to launch it automatically in containerized environments; the image reportedly had over 100,000 pulls before removal. The campaign targeted AWS customer compute resources, especially ECS clusters and EC2 fleets, including aggressive use of Auto Scaling Groups and high-resource task definitions to maximize mining capacity. Associated infrastructure and indicators mentioned in the reporting include mining domains asia[.]rplant[.]xyz, eu[.]rplant[.]xyz, and na[.]rplant[.]xyz, and use of the randomvirel algorithm. The broader intrusion activity included reconnaissance of EC2 quotas and permissions via RunInstances DryRun calls, disabling EC2 API termination through ModifyInstanceAttribute to hinder remediation, and creation of a public unauthenticated Lambda Function URL for persistence; an IAM user with AmazonSESFullAccess was also created, indicating possible follow-on phishing use. The activity was detected by Amazon GuardDuty across multiple customer accounts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency-mining malware deployed into victim AWS environments (ECS/EC2) using compromised IAM credentials with admin-like privileges to consume compute resources for illicit mining.
SBRMiner-MULTI is a cryptominer deployed via malicious Docker images to mine cryptocurrency on compromised AWS EC2 and ECS instances, leveraging stolen IAM credentials and persistence mechanisms to maximize illicit mining profits.
SBRMiner-MULTI is a cryptocurrency mining malware deployed via malicious Docker images in compromised AWS environments. It is designed to mine cryptocurrency by hijacking cloud compute resources, using all available processor cores, and connecting to specific mining pools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.