logo

Threat Alert: Threat Actors Using release

ID: 33c4bcdf-b898-5aa5-bc94-53c7d1b726ea

STIX ID: report--33c4bcdf-b898-5aa5-bc94-53c7d1b726ea

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2021-11-03

Date Updated: 2026-04-26

...
...

Aqua’s Team Nautilus observed a cryptocurrency-mining campaign that used a container escape via Linux cgroups' release_agent from a privileged container to execute host-level code; the attacker image contained XMRig (renamed nginx) and a 'calm.sh' script that kills competitor miners and modifies /release_agent. The report provides technical analysis, MD5 indicators, Tracee event output, and a Rego signature to detect the behavior, and recommends avoiding privileged containers and using runtime detection tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.