Researchers identified Denonia, a Go-based 64-bit ELF malware strain described as the first known malware observed targeting AWS Lambda in the wild. The binary masquerades as python and contains a customized version of the XMRig cryptocurrency miner, indicating the operators aimed to hijack serverless compute resources for illicit mining rather than exploit a flaw in Amazon's platform itself.
Analysis found that Denonia checks for AWS Lambda environment variables before running and uses DNS over HTTPS to contact its command-and-control domain, gw.denonia[.]xyz, helping it evade traditional network monitoring and controls. Investigators said the initial access vector remains unknown but likely involved compromised AWS credentials instead of an AWS vulnerability, while Amazon stated that Lambda is secure by default and that the malware does not abuse any weakness in Lambda or other AWS services.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A 64-bit ELF Denonia sample masquerading as "python" was uploaded to VirusTotal. The Go-based malware contained a customized XMRig cryptocurrency miner and checked for AWS Lambda environment variables before execution.
A Denonia sample named "bc50541af8fe6239f0faa7c57a44d119.virus" was uploaded to VirusTotal. Researchers later linked it to the malware family targeting AWS Lambda.
Amazon stated that Lambda remained secure by default and that the malware did not exploit any weakness in Lambda or other AWS services. The company said the activity instead relied on fraudulently obtained account credentials.
Cado Labs discovered and analyzed Denonia, describing it as the first malware observed in the wild targeting Amazon Web Services' Lambda serverless platform. The malware used DNS over HTTPS for command-and-control traffic and appeared likely to rely on compromised AWS credentials rather than an AWS vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.