Commando Cat campaign (Campaign)
ID: 3c2b9117-f1eb-5ed6-bce6-b8b76e44896b
STIX ID: report--3c2b9117-f1eb-5ed6-bce6-b8b76e44896b
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-02-01
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The report describes the Commando Cat campaign that compromises vulnerable Docker instances by deploying a harmless container and escaping it (using chroot) to execute payloads on the host. Post-exploitation actions include credential theft (including cloud credentials via IMDS abuse), dropping a shell-script backdoor that can add SSH keys and create a 'games' user with a known password, modifying /etc/sudoers, and deploying a cryptocurrency miner; the campaign uses diskless techniques to avoid forensic artifacts and shows overlaps with TeamTNT-like cryptojacking operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
