logo

Commando Cat campaign (Campaign)

ID: 3c2b9117-f1eb-5ed6-bce6-b8b76e44896b

STIX ID: report--3c2b9117-f1eb-5ed6-bce6-b8b76e44896b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
72/100

Date Published: 2024-02-01

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report describes the Commando Cat campaign that compromises vulnerable Docker instances by deploying a harmless container and escaping it (using chroot) to execute payloads on the host. Post-exploitation actions include credential theft (including cloud credentials via IMDS abuse), dropping a shell-script backdoor that can add SSH keys and create a 'games' user with a known password, modifying /etc/sudoers, and deploying a cryptocurrency miner; the campaign uses diskless techniques to avoid forensic artifacts and shows overlaps with TeamTNT-like cryptojacking operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.