
SCARLETEEL: AWS Fargate Breach to Cloud Crypto-Mining
An internet-reachable JupyterLab notebook on AWS Fargate was exploited for code execution. The operator stole the task role credentials from the container metadata endpoint, replayed them to harvest Secrets Manager and SSM secrets, minted a new access key for persistence, read the Terraform state and a customer-ledger export, and finished by launching compute-optimized instances to mine cryptocurrency. Work the CloudTrail audit trail alongside the SIEM proxy, DNS, and firewall egress records to reconstruct the chain.
Launches in 5 days
Tuesday, October 6, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free