{"id":45150,"date":"2022-02-04T00:00:00","date_gmt":"2022-02-04T00:00:00","guid":{"rendered":"urn:uuid:cb726bdd-a4dc-1fe9-b516-e99a4ba667eb"},"modified":"2022-02-04T00:00:00","modified_gmt":"2022-02-04T00:00:00","slug":"cryptojacking-attacks-target-alibaba-ecs-instances","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/","title":{"rendered":"Cryptojacking Attacks Target Alibaba ECS Instances"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/cryptojacking-alibaba.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <!-- Begin mPulse library --> <!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"In this article, learn about a recent cryptojacking attacks resulting in disabled features in Alibaba Cloud ECS instances, which allowed for illicit mining of the Monero cryptocurrency.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"workload security,cloud native,research,article,aws\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"defaultArticleWithoutHero\"> <meta property=\"article:published_time\" content=\"2022-02-04\"> <meta property=\"article:tag\" content=\"workload security\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances.html\"> <title>Cryptojacking Attacks Target Alibaba ECS Instances<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances.html\"><br \/>\n<meta property=\"og:title\" content=\"Cryptojacking Attacks Target Alibaba ECS Instances\"><br \/>\n<meta property=\"og:description\" content=\"In this article, learn about a recent cryptojacking attacks resulting in disabled features in Alibaba Cloud ECS instances, which allowed for illicit mining of the Monero cryptocurrency.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/cryptojacking-alibaba.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Cryptojacking Attacks Target Alibaba ECS Instances\"><br \/>\n<meta name=\"twitter:description\" content=\"In this article, learn about a recent cryptojacking attacks resulting in disabled features in Alibaba Cloud ECS instances, which allowed for illicit mining of the Monero cryptocurrency.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/cryptojacking-alibaba.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business context-devops\" id=\"readabilityBody\" readability=\"50.437140299271\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1835447412\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"7.7323420074349\">\n<div class=\"article-details\" role=\"heading\" readability=\"34.795539033457\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Workload Security<\/p>\n<p class=\"article-details__description\">Discover how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero.<\/p>\n<p class=\"article-details__author-by\">By: Alfredo de Oliveira <time class=\"article-details__date\">February 04, 2022<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"45.227368421053\">\n<div readability=\"36.96\">\n<p>Cryptojacking attacks continue to increase. Unlike ransomware, cryptojacking cybercriminals make their money staying silent and undetected, leeching the computer power from their target to mine valuable cryptocurrency. Cryptomining can cause serious downtime for developers by draining the enterprise\u2019s processing power. It can also cause subscription bills to skyrocket\u2014especially if you\u2019re utilizing an auto-scale feature.<\/p>\n<p>It\u2019s been known that threat actors are actively exploiting misconfigured Linux-powered servers, regardless of whether they run on-premises or in the cloud. One notorious <a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/news\/cybercrime-and-digital-threats\/teamtnt-activities-probed\" target=\"_blank\" rel=\"noopener\">example<\/a> is TeamTNT, one of the first hacking groups shifting its focus to cloud-oriented services.<\/p>\n<p>The cryptojacking battlefield is shared by multiple threat actors such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/k\/analysis-of-kinsing-malwares-use-of-rootkit.html\">Kinsing<\/a> and TeamTNT. Two code characteristics these groups share is to remove competing actors who are also mining for cryptocurrency and disable security features found in the victim machine. This provides them <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/i\/war-of-linux-cryptocurrency-miners-a-battle-for-resources.html\">an advantage<\/a> over the hijacked resources, like the <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/j\/actors-target-huawei-cloud-using-upgraded-linux-malware-.html\">advanced system sanitation<\/a> that we identified targeting Huawei Cloud.<\/p>\n<p>In this article, we focus on one common functionality found among multiple payloads: the disabling of features inside cloud service provider (CSP), Alibaba. We also look at possible reasons that multiple threat actors and malware routines focused on Alibaba Cloud (also known as Aliyun) and the implications of these illicit mining activities on Alibaba Cloud users.<\/p>\n<p><span class=\"body-subhead-title\">Looking into Alibaba ECS<\/span><\/p>\n<p>Alibaba Elastic Computing Service (ECS) instances come with a preinstalled security agent. As a result, the threat actors try to uninstall it upon compromise. This is no surprise as we have seen similar payloads in the past. However, this time we found a specific code in the malware creating firewall rules to drop incoming packets from IP ranges belonging to internal Alibaba zones and regions.<br \/>&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure1.jpg\" alt=\"figure1\"><figcaption>Figure 1. One sample of an Alibaba ECS instance with the specific malicious code creating firewall rules<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure2.jpg\" alt=\"figure2\"><figcaption> Figure 2. Disabling the Alibaba security agent<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37.5\">\n<div readability=\"20\">\n<p>In addition, the default Alibaba ECS instance provides root access. While other CSPs provide different options ranging from the least privileged ones \u2014 such as not allowing Secure Shell (SSH) authentication over users and passwords and only allowing asymmetric cryptography authentication \u2014 other CSPs do not allow the user to log in via SSH directly by default, so a less privileged user is required.<\/p>\n<p>For instance, if the login secrets are leaked, having low-privilege access would require more effort to escalate the privileges. However, with Alibaba, all users have the option to give a password straight to the root user inside the virtual machine (VM).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure3.png\" alt=\"figure3\"><figcaption> Figure 3. Root permissions on a default Alibaba ECS instance<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37.605363984674\">\n<div readability=\"22.177522349936\">\n<p>Security wise, this is in contradiction with the <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/b\/12-azure-aws-security-best-practices.html\">principle of least privilege<\/a>, and it should be emphasized that this is the responsibility of the user for a secure configuration. We highly recommend creating a less privileged user for running applications and services within the ECS instance.<\/p>\n<p>In this situation, the threat actor has the highest possible privilege upon compromise, including vulnerability exploitation, any misconfiguration issue, weak credentials, or data leakage. Thus, advanced payloads such as kernel module rootkits and achieving persistence via running system services can be deployed. Given this feature, it comes as no surprise that multiple threat actors target Alibaba ECS simply by inserting a code snippet only found in the service for removing software.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure4.png\" alt=\"figure4\"><figcaption> Figure 4. A diamorphine deployment as an example of high-privilege abuse<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.986870897155\">\n<div readability=\"11.816192560175\">\n<p><span class=\"body-subhead-title\">Cryptojacking Aliyun<\/span><\/p>\n<p>When a cryptojacking malware is running inside Alibaba ECS, the security agent installed will send a notification of a malicious script running. It then becomes the responsibility of the user to stop the ongoing infection and malicious activities. Alibaba Cloud Security Center provides <a href=\"https:\/\/www.alibabacloud.com\/help\/faq-detail\/41206.htm?spm=a2c63.q38357.a3.9.345c54ff6EWeD8\" target=\"_blank\" rel=\"noopener\">a guide<\/a> on how to do this. More importantly, it is always the responsibility of the user to prevent this infection from happening in the first place.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure5.png\" alt=\"figure5\"><figcaption> Figure 5. An example of cryptojacking malware<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37.60621761658\">\n<div readability=\"20.782383419689\">\n<p>Despite detection, the security agent fails to clean the running compromise and gets disabled. Looking at another malware sample shows that the security agent was also uninstalled before it could trigger an alert for compromise. The samples then proceeded to install the cryptojacking malware XMRig. Examining the samples further shows the cryptominer can easily be replaced with another malware to execute in the environment.<\/p>\n<p>It is also important to note that Alibaba ECS has an <a href=\"https:\/\/www.alibabacloud.com\/help\/product\/25855.htm\" target=\"_blank\" rel=\"noopener\">auto scaling<\/a> feature, wherein users and organizations can enable the service to automatically adjust computing resources based on the volume of user requests. When the demand increases, auto scaling allows the Alibaba ECS instances to serve the said requests according to the enumerated policies. While the feature is given to subscribers at no extra cost, the increase in resource usage prompts the additional charges. By the time the billing arrives to the unwitting organization or user, the cryptominer has likely already incurred additional costs. Additionally, the legitimate subscribers have to manually remove the infection to clean the infrastructure of the compromise.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure6.png\" alt=\"figure6\"><figcaption> Figure 6. An example of a security agent uninstallation routine used by the malware<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.205479452055\">\n<div readability=\"11.178082191781\">\n<p>The samples our team acquired can be tied to campaigns targeting Alibaba, and we found these samples sharing common traits, functions, and functionalities with <a href=\"https:\/\/threatpost.com\/cryptomining-malware-uninstalls-cloud-security-products\/140959\/\" target=\"_blank\" rel=\"noopener\">other campaigns<\/a> that also target CSPs such as Huawei Cloud.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/figure7.png\" alt=\"figure7\"><figcaption>Figure 7. Comparing samples of compromised Alibaba Cloud (left) and Huawei Cloud (right).<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"40.43553008596\">\n<div readability=\"27.919770773639\">\n<p>The samples from both campaigns share common traits, especially when it comes to removing \u201cadversaries\u201d and setting up the environment for next-phase infections, such as making sure to use a public domain name system (DNS). Although the style in coding is different, the purpose of the functions is similar on both attacks.<\/p>\n<p><span class=\"body-subhead-title\">Mitigating the impact of threats on Alibaba ECS workloads<\/span><\/p>\n<p>Now that we\u2019ve covered the basics of cryptojacking malware on Alibaba ECS, here are some best practices to mitigate risks:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Follow the shared responsibility model: While CSPs are responsible for securing the service, users must ensure security configurations of workloads, projects, and environments are safe. Read through the <a href=\"https:\/\/partners-intl.aliyun.com\/vodafone\/trust-center\" target=\"_blank\" rel=\"noopener\">Alibaba Cloud guides<\/a>, customize, and enable the security layers of workloads and projects accordingly. Make sure it has more than one layer of malware-scanning and vulnerability-detection tools.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Customize the security features of cloud projects and workloads: Avoid running applications under root privilege and using passwords for SSH. Use public key cryptography for access.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Adhere to the principle of least privilege: Only grant users with the highest access privileges according to their respective levels of involvement in a project or an application.<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">Indicators of Compromise (IOCs)<\/span><\/p>\n<p>You can find the full list of IOCs and Trend Micro detections <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/k\/groups-target-alibaba-ecs-instances-for-cryptojacking\/IOCs-groups-target-alibaba-ecs-instances-cryptojacking.txt\">here<\/a><\/p>\n<p><span class=\"body-subhead-title\">Solution<\/span><\/p>\n<p>Security solutions such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud.html\">Trend Micro Cloud One\u2122<\/a> protect cloud-native systems and their various layers. By leveraging Trend Micro Cloud One\u2122, enterprises gain access to protection for continuous integration and continuous delivery (CI\/CD) pipeline and applications. The Trend Micro Cloud One platform includes <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-workload-security.html\">Workload Security<\/a> runtime protection for workloads.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"devopsrc-ba73c8\" href=\"https:\/\/www.trendmicro.com\/en_us\/business\/campaigns\/cloud-one-trial.html\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/trial-banners\/cloud-one-trial-banner.jpg\" alt=\"cloud-one-trial\"> <\/a> <\/figure>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Discover how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":45151,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9503,9505,9501,9618,9500],"class_list":["post-45150","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-devops-article","tag-trend-micro-devops-aws","tag-trend-micro-devops-cloud-native","tag-trend-micro-devops-research","tag-trend-micro-devops-workload-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-04T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/cryptojacking-alibaba.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Cryptojacking Attacks Target Alibaba ECS Instances\",\"datePublished\":\"2022-02-04T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/\"},\"wordCount\":1167,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg\",\"keywords\":[\"Trend Micro DevOps : Article\",\"Trend Micro DevOps : AWS\",\"Trend Micro DevOps : Cloud Native\",\"Trend Micro DevOps : Research\",\"Trend Micro DevOps : Workload Security\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/\",\"name\":\"Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg\",\"datePublished\":\"2022-02-04T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg\",\"width\":1199,\"height\":594},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cryptojacking-attacks-target-alibaba-ecs-instances\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro DevOps : Article\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-devops-article\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Cryptojacking Attacks Target Alibaba ECS Instances\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/","og_locale":"en_US","og_type":"article","og_title":"Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-02-04T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/22\/b\/cryptojacking-attacks-target-alibaba-ecs-instances\/cryptojacking-alibaba.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Cryptojacking Attacks Target Alibaba ECS Instances","datePublished":"2022-02-04T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/"},"wordCount":1167,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg","keywords":["Trend Micro DevOps : Article","Trend Micro DevOps : AWS","Trend Micro DevOps : Cloud Native","Trend Micro DevOps : Research","Trend Micro DevOps : Workload Security"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/","url":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/","name":"Cryptojacking Attacks Target Alibaba ECS Instances 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg","datePublished":"2022-02-04T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/02\/cryptojacking-attacks-target-alibaba-ecs-instances.jpg","width":1199,"height":594},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cryptojacking-attacks-target-alibaba-ecs-instances\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro DevOps : Article","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-devops-article\/"},{"@type":"ListItem","position":3,"name":"Cryptojacking Attacks Target Alibaba ECS Instances"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=45150"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45150\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/45151"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=45150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=45150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=45150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}