Attacker Targets Hadoop YARN, Flint Servers in Stealthy Campaign
ID: 0a731148-5e0f-5042-80e4-0c9ae70ede02
STIX ID: report--0a731148-5e0f-5042-80e4-0c9ae70ede02
Feed Name: Dark Reading
Threat Score
Aqua Nautilus researchers observed attacks exploiting known misconfigurations in Hadoop YARN and Apache Flink to remotely execute code and deploy packed ELF payloads that install rootkits and a Monero cryptominer; the adversary used cron job deletion/creation, /tmp wiping, packed and stripped ELF binaries, permission changes, and dual rootkits to persist and evade detection on high-CPU big-data servers, raising risks of resource abuse, lateral movement, and potential data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
