Recommended Free Tools
Denonia is malware reported in 2022 as specifically designed to run in AWS Lambda. Researchers analyzing samples described a Go-written program that ran a customized XMRig cryptocurrency miner in memory. They did not identify how the malware was deployed, so there is no confirmed initial-access method to attribute to Denonia.
What is Denonia malware?
Denonia is the name given to malware that Cado Security described as the first publicly known case specifically designed for AWS Lambda, Amazon Web Services’ serverless compute platform. FortiGuard Labs also reported on the sample in April 2022. These are findings about analyzed samples; they do not establish how widespread Denonia was or whether Lambda environments generally were affected.
The available reporting supports a historical account of a Lambda-targeting threat, not a current estimate of its prevalence or ongoing activity.
How did Denonia target AWS Lambda?
FortiGuard Labs reported that Denonia was written in Go and contained a customized version of XMRig, a cryptocurrency-mining program. The miner ran in memory and communicated with an attacker’s mining pool, using compute resources to mine cryptocurrency.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
The reports do not establish a confirmed exploit chain, a particular vulnerability, or another specific way Denonia entered a Lambda environment. Cado Security and FortiGuard Labs both said the deployment method or attack vector had not been identified. A credential compromise or software vulnerability should therefore be treated only as a possibility, not as a documented fact about Denonia.
How can you detect cryptocurrency mining in Lambda?
AWS GuardDuty documents the finding type CryptoCurrency:Lambda/BitcoinTool.B for Lambda network activity involving an IP address associated with cryptocurrency-related activity. AWS assigns this finding High severity by default. It is a signal to investigate, not a guarantee that GuardDuty will identify every Denonia sample or every form of mining.
Rank #2
AWS advises checking whether the function’s behavior is expected. Its guidance says: “If this activity is unexpected, the security best practice is to assume that Lambda has been potentially compromised and follow the remediation recommendations.” Authorized blockchain-related activity may explain a finding; AWS documents narrowly scoped suppression rules based on the finding type and function name for such cases.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What AWS Lambda safeguards are useful today?
AWS’s Lambda security guidance recommends layered operational safeguards. These are general security practices, not proof that Denonia will be prevented or detected.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Limit permissions: Give each function only the IAM permissions it needs, rather than broad account access.
- Monitor network activity: Use GuardDuty Lambda Protection to monitor Lambda network activity and review relevant findings.
- Watch function health: Use CloudWatch metrics and alarms to surface unusual function behavior.
- Track unexpected spending: Use AWS Cost Anomaly Detection to flag unusual usage or cost patterns that may merit investigation.
If a cryptocurrency-related finding is unexpected, investigate the function and follow AWS’s remediation recommendations. A cost or monitoring alert can help identify unusual activity, but it does not by itself establish that Denonia is present.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

