Threat Alert: Threat Actors Using release
ID: 33c4bcdf-b898-5aa5-bc94-53c7d1b726ea
STIX ID: report--33c4bcdf-b898-5aa5-bc94-53c7d1b726ea
Feed Name: Aqua Security Blog
Aqua’s Team Nautilus observed a cryptocurrency-mining campaign that used a container escape via Linux cgroups' release_agent from a privileged container to execute host-level code; the attacker image contained XMRig (renamed nginx) and a 'calm.sh' script that kills competitor miners and modifies /release_agent. The report provides technical analysis, MD5 indicators, Tracee event output, and a Rego signature to detect the behavior, and recommends avoiding privileged containers and using runtime detection tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
