logo

Cloud-y Linux Malware Rains on Apache, Docker, Redis & Confluence

ID: 4d9eb8c8-eed3-52b9-aa2c-959d1662d193

STIX ID: report--4d9eb8c8-eed3-52b9-aa2c-959d1662d193

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-03-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Cado Security observed a campaign called "Spinning YARN" that scans for cloud misconfigurations and an RCE in Confluence (CVE-2022-26134) to compromise servers running Hadoop YARN, Confluence, Docker, and Redis. The actor deploys Golang payloads, a Monero miner (XMRig), the Platypus reverse shell, and user-mode rootkits to establish persistence and evade detection, indicating active exploitation of Internet-facing cloud services and container environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.