AWS EC2 Forensic Investigation: Analyzing a RegreSSHion Compromise
When an AWS abuse report lands in your inbox about an EC2 instance running cryptocurrency mining malware, you know you’re in for an interesting investigation. This week, I conducted a complete forensic analysis of a compromised production server, and the findings highlight critical lessons about patch management, monitoring, and security hygiene. Initial Discovery The timeline started simple: AWS abuse report in December, 2025, about suspicious network activity. The client had already rebuilt a clean instance, but the compromised server remained running for forensic analysis. My task was to determine what happened, how it happened, and ensure the replacement was truly clean. ...