logo

Looney Tunables Vulnerability Exploited by Kinsing

ID: 6456f666-2769-530b-8b6e-a741c727ad22

STIX ID: report--6456f666-2769-530b-8b6e-a741c727ad22

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2023-11-03

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers intercepted an active Kinsing campaign targeting cloud-native environments where attackers exploited a PHPUnit vulnerability (CVE-2017-9841) to deploy a reverse shell, manually tested and executed a Looney Tunables local privilege escalation exploit (CVE-2023-4911) to attempt root access, deployed obfuscated PHP/JS backdoors and attempted to harvest AWS instance metadata and temporary credentials; the report provides observed IOCs, MITRE ATT&CK mappings, detection guidance, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.