Skip to main content
SCARLETEEL: AWS Fargate Breach to Cloud Crypto-Mining operation cover
COMING SOONIntermediate

SCARLETEEL: AWS Fargate Breach to Cloud Crypto-Mining

An internet-reachable JupyterLab notebook on AWS Fargate was exploited for code execution. The operator stole the task role credentials from the container metadata endpoint, replayed them to harvest Secrets Manager and SSM secrets, minted a new access key for persistence, read the Terraform state and a customer-ledger export, and finished by launching compute-optimized instances to mine cryptocurrency. Work the CloudTrail audit trail alongside the SIEM proxy, DNS, and firewall egress records to reconstruct the chain.

55m
7 tasks
50 points
Free

Launches in 5 days

Oct 6, 2026

Tuesday, October 6, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

CloudSIEMFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Establish where the intrusion began
2Classify how the cloud credentials were stolen
3Identify the stolen workload identity
4Find the secret that was retrieved in plaintext
5Pin the persistence the operator established
6Trace the data exfiltration egress
7Classify the final impact technique

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free