logo

Attacker Targets Hadoop YARN, Flint Servers in Stealthy Campaign

ID: 0a731148-5e0f-5042-80e4-0c9ae70ede02

STIX ID: report--0a731148-5e0f-5042-80e4-0c9ae70ede02

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Aqua Nautilus researchers observed attacks exploiting known misconfigurations in Hadoop YARN and Apache Flink to remotely execute code and deploy packed ELF payloads that install rootkits and a Monero cryptominer; the adversary used cron job deletion/creation, /tmp wiping, packed and stripped ELF binaries, permission changes, and dual rootkits to persist and evade detection on high-CPU big-data servers, raising risks of resource abuse, lateral movement, and potential data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.