/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How Hackers Hid a Money-Mining Botnet in the Clouds of Amazon and Others

Hackers have long used malware to enslave armies of unwitting PCs, but security researchers Rob Ragan and Oscar Salazar had a different thought: Why steal computing resources from innocent victims when there's …

Wired Andy Greenberg

Context & Ripple Effects

The botnet story has been migrating for years: researchers were tracking botnets used by hackers back in 2009, when the machines being enslaved were consumers' desktops — including a wave of Mac-based botnets that same spring. The premise of this report inverts that model: security researchers Rob Ragan and Oscar Salazar describe attackers who skip victim PCs entirely and rent their mining capacity straight from cloud providers like Amazon.

The idea of Amazon's cloud as criminal territory is not new either — in November 2011 researchers found Amazon cloud servers teeming with backdoors and other people's data. What changed by mid-2014 is the motive: instead of using rented instances as staging points for fraud, the operators here are running the money-making workload itself on someone else's bill.

First-order effects

  • Cloud providers such as Amazon absorb the direct loss: stolen compute shows up as unpaid or fraudulent usage on their infrastructure rather than as degraded performance on end users' machines.
  • The traditional botnet defense — cleaning infected PCs — misses these operators entirely, so detection responsibility shifts to the provider's account-abuse and billing-fraud systems.

Second-order effects

  • Providers face pressure to profile workloads, not just logins: a mining operation looks legitimate at sign-up and only reveals itself in sustained compute patterns, pushing Amazon and rivals toward usage-anomaly monitoring as a standard control.
  • If cloud accounts become the preferred botnet substrate, the economics favor attackers who can scale stolen capacity on demand — undercutting the old constraint where a botnet's size was capped by how many machines it could infect.

Third-order effects

  • As enterprise workloads settle in the cloud, the botnet category itself splits: endpoint malware campaigns persist alongside account-takeover operations that weaponize rented infrastructure, forcing the security industry to treat identity and billing telemetry as attack surface.
  • Regulators and insurers will eventually have to decide who eats cloud-fraud losses — the provider whose platform was abused or the customer whose credentials were stolen — a question the PC-era botnet model never had to answer.

The trend: Botnet economics are following computing power into the cloud, trading hijacked PCs for hijacked accounts and making cloud providers the new battleground for resource-theft detection.