CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
ID: ff802a3f-b4bf-58e6-9a54-ab2c7b4d45d7
STIX ID: report--ff802a3f-b4bf-58e6-9a54-ab2c7b4d45d7
Feed Name: The Register (Security)
Threat Score
CAI (Cloud AI Infrastructure Attack Framework) is a centralized cloud-native worm observed by Hunt.io that scans and exploits infrastructure (Docker, Kubernetes, Redis, etcd, Kubelet, Ray) to steal credentials, install cryptominers and a Python backdoor, and actively kills competitor secret-stealing malware to monopolize compromised hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
