Cloud-y Linux Malware Rains on Apache, Docker, Redis & Confluence
ID: 4d9eb8c8-eed3-52b9-aa2c-959d1662d193
STIX ID: report--4d9eb8c8-eed3-52b9-aa2c-959d1662d193
Feed Name: Dark Reading
Threat Score
Cado Security observed a campaign called "Spinning YARN" that scans for cloud misconfigurations and an RCE in Confluence (CVE-2022-26134) to compromise servers running Hadoop YARN, Confluence, Docker, and Redis. The actor deploys Golang payloads, a Monero miner (XMRig), the Platypus reverse shell, and user-mode rootkits to establish persistence and evade detection, indicating active exploitation of Internet-facing cloud services and container environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
