Earlier quoted context omitted.
Did you get to a root cause of how the “crypto hackers” “took over” your account, or of what the “very advanced” scripts did?
We had basic security like MFA set up and we never shared keys, so we don't understand until this day how they managed to take over. The attack resembled a very aggressive, clever virus so the people behind it definitely had very advance knowledge of AWS. They could enable regions we had disabled and recreate roles that were deleted in a matter of minutes, again MFA on, no keys. AWS kept giving us conflicting instruc…
In what way did the attack resemble a very aggressive, clever virus?
Do you mean that it happened fast? How do you know it wasn't something simple like your credentials leaking?