Palo Alto Networks Unit 42 reported that exposed AWS IAM access keys were used in malicious operations that rapidly turned compromised cloud accounts into platforms for cryptojacking and broader resource abuse. Attackers leveraged valid IAM credentials to gain access without exploiting software flaws, then provisioned compute resources and manipulated cloud services to mine cryptocurrency while consuming victims’ infrastructure and budget.
The activity highlights how leaked cloud credentials can enable fast, low-friction compromise across internet-facing environments, especially when keys are overprivileged or insufficiently monitored. Unit 42’s findings underscore that exposed IAM keys can support sustained unauthorized operations inside cloud tenants, making credential hygiene, least-privilege access, key rotation, and continuous monitoring of anomalous cloud activity critical defensive measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a report titled "CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys," describing malicious operations involving exposed cloud IAM keys, including cryptojacking activity.
Palo Alto Networks Unit 42 published research titled "Compromised Cloud Compute Credentials: Case Studies From the Wild," documenting real-world cases involving compromised cloud compute credentials. The report represents an earlier disclosure of cloud credential abuse activity preceding its later IAM key research.
Palo Alto Networks Unit 42 published research describing TeamTNT operations targeting cloud environments and actively enumerating cloud resources. The report documents an earlier phase of cloud-focused threat activity preceding Unit 42's later publications on compromised compute credentials and exposed IAM keys.
3 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.