Denonia Malware
Summary
A piece of intrusive malware named Denonia is being used in threatening operations targeting Amazon Web Services (AWS) Lambda installations. XMRig is a popular crypto-miner often used by cybercriminals to hijack the hardware resources of the breached device to mine for the Monero cryptocurrency. After analyzing the threat, researchers discovered that despite having the file name python, Denonia was created using the Go programming language. The researchers speculate that Denonias curious use of DNS over HTTPS (DOH) achieved via the doh-go library was implemented as a countermeasure to stop AWS from detecting the threats lookups due to its unsafe domains. At the moment, no conclusive evidence pointing to the exact infection vector used in the attacks involving Denonia malware has been found.