Denonia Malware Shows Evolving Cloud Threats

MuzzMelbourne

Level 15
Thread author
Verified
Top Poster
Well-known
Mar 13, 2022
544
3,920
1,369
Australia
One of the more important points to get across when addressing cloud security is to make it clear to all involved that cloud security is not only different, but that it keeps evolving. If security professionals needed a reminder of this, they need to look no further than the recent discovery of Denonia, a cryptominer that operates in serverless environments.

 
Using DoH is a fairly unusual choice for the Denonia authors, but provides two advantages here:
  • AWS cannot see the dns lookups for the malicious domain, reducing the likelihood of triggering a detection