logo

Threat Actors Hijack Misconfigured Servers for Live Sports Streaming

ID: 82f459ad-fb8b-5338-be28-0f66ffc78f22

STIX ID: report--82f459ad-fb8b-5338-be28-0f66ffc78f22

Feed Name: Aqua Security Blog

Threat Score
45/100

Date Published: 2024-11-19

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers used honeypots and runtime forensics (Aqua Tracee and Traceeshark) to uncover threat actors exploiting unauthenticated, internet-exposed JupyterLab/Notebook instances to install and run ffmpeg, capture live sports feeds, and re-stream them to external platforms for illicit monetization. The report documents the attack flow, captured commands and artifacts (including an ffmpeg MD5 and attacker IPs), maps techniques to MITRE ATT&CK, and provides detection and mitigation recommendations for securing Jupyter deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.