logo

Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

ID: 9835424e-3db8-505e-aadb-bcddf57c19f0

STIX ID: report--9835424e-3db8-505e-aadb-bcddf57c19f0

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-04-27

...
...

This report analyzes a TeamPCP cloud-native intrusion scenario, tracing an end-to-end container compromise: initial download-and-pipe execution, Kubernetes discovery and API abuse, lateral movement via a kube.py script, attempts at persistence (systemd), runtime tooling installation, tunneling/proxy establishment, base64-encoded payload reconstruction, miner deployment for monetization, and escalation to node-level control via privileged DaemonSets; the analysis maps these behaviors to detection rules and the MITRE ATT&CK framework to demonstrate detection engineering for container and control-plane telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.