Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Denonia is malware reported in April 2022 that was built to run in AWS Lambda and mine cryptocurrency. Its case is an early public example of malware adapted to a serverless cloud environment—but published analyses did not establish how it was deployed, and they did not report confirmed data theft or destructive activity by the malware.

What is Denonia malware?

Security researchers at Cado Security described Denonia as the first publicly reported malware specifically designed to execute in AWS Lambda, Amazon’s serverless compute service. FortiGuard Labs’ April 2022 analysis characterized its observed purpose as cryptojacking: using computing resources to mine cryptocurrency.

The reported samples were Linux ELF binaries written in Go. Researchers found customized XMRig mining code, which Denonia executed in memory, and FortiGuard reported communication with a mining pool. Cado also noted binary padding and DNS over HTTPS (DoH), which sends DNS queries over encrypted HTTPS connections rather than conventional DNS.

Those findings describe analyzed samples, not every possible use of the name or every later incident. The reporting established cryptocurrency mining behavior; it did not establish that Denonia stole data or carried out destructive activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did Denonia target AWS Lambda?

Denonia’s significance lies in its adaptation to a serverless runtime. A Lambda function runs in response to events or invocations, rather than as a conventional server that an operator manages directly. A malicious workload in that environment can therefore look different from malware running on a persistent virtual machine: invocation patterns, function permissions, deployment activity, and associated cloud identity events all matter alongside file and network indicators.

In its analysis, Cisco Talos discussed compromised credentials as a possible way an attacker could gain access and deploy or execute a function. It also considered DoH a possible means of communication or of avoiding network-layer detection. These were hypotheses, not a confirmed Denonia delivery chain. Cado and FortiGuard both reported that the attack or deployment vector had not been identified. Cisco said it had no known successful deployments at the time of its 2022 article; that statement applies to the reporting available then, not to all activity since.

DoH is relevant to defenders because conventional DNS monitoring may not reveal queries carried inside HTTPS. That can make domain- or IP-based matching incomplete; an indicator match is useful, but its absence does not rule out suspicious activity.

What changed in later reported samples?

Cado later reported additional ELF samples for ARM64 and x86_64, both architectures supported by Lambda. The later samples retained XMRig mining code executed from memory and used heavier obfuscation than the original samples.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported sample characteristics Original samples Later samples
Architectures Architecture details are not stated in the cited summary of the original samples. ARM64 and x86_64, reported by Cado.
Mining behavior Customized XMRig code executed in memory. XMRig code continued to be embedded and executed in memory.
Obfuscation Binary padding was noted. Cado described heavier obfuscation.
DNS over HTTPS package DoH was a notable feature in the original analysis. Some samples lacked a DoH package. Cado left open whether this reflected evasion or an earlier variant.

The reported differences do not prove a simple progression from one fixed version to another, nor do they establish why some later samples lacked DoH code. The evidence supports changes in reported files, not a definitive account of the malware’s development history.

How can you detect possible cryptomining in AWS Lambda?

Use multiple kinds of evidence. Cisco Talos describes an “AWS Lambda Invocation Spike” alert for unusually high invocation behavior, alongside identity- and account-focused detections such as unusual regional API usage and MFA changes. These are vendor-described alert examples, not a guarantee that a specific alert will catch Denonia or every cryptomining workload.

  • Look for behavioral anomalies: Review invocation patterns and investigate unexpected increases in activity, especially when they coincide with unfamiliar function or account changes.
  • Correlate identity and API activity: Examine unusual regional API usage, unexpected authentication or MFA changes, and other account events alongside function activity.
  • Use network indicators with context: Check relevant domain and IP indicators, but do not treat a clean match result as proof of safety. DoH can reduce the visibility of conventional DNS monitoring.
  • Investigate the function and its access: Review function code, deployment and configuration changes, permissions, and network connections as part of the same timeline. A suspicious signal alone does not establish that Denonia is present.

These checks are a defensive starting point rather than a Denonia-specific signature set. The cited reporting does not establish a complete indicator list or a single detection that identifies every sample.

What does the case mean for AWS Lambda security?

Managed serverless infrastructure does not remove the customer’s responsibility to secure the functions they create and the access and connections those functions use. Cisco’s discussion of Denonia emphasizes protecting function access, code, and network connections. Function permissions and deployment credentials deserve attention alongside runtime monitoring because a cloud workload may be introduced through account or identity activity rather than through a traditional server exploit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS’s malware-analysis guidance addresses how to investigate suspicious software safely. It recommends containment measures such as a dedicated, isolated VPC or account, restricted access and egress, CloudTrail logging, GuardDuty monitoring, permission boundaries, and lifecycle and budget controls. Those are general lab-safety practices, not Denonia-specific remediation instructions. Do not run a suspicious sample in a production account or an environment with unrestricted access to other systems.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Denonia does—and does not—show about evolving cloud threats

Cado’s 2023 cloud report argued that serverless functions remained attractive for cryptojacking and warned that cloud attackers could broaden their objectives. That is a broader assessment and forecast, not evidence that Denonia itself later shifted to credential theft or destructive behavior. Likewise, the public reporting summarized here does not establish Denonia’s current campaign status or confirm later successful deployments.

The practical lesson is narrower and more useful: cloud-native malware can be tailored to a managed runtime, so defenders should combine workload behavior, identity activity, and network evidence rather than rely only on traditional host signatures. Denonia demonstrated that possibility; the documented samples’ observed behavior was cryptocurrency mining.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.