Threat Actors Hijack Misconfigured Servers for Live Sports Streaming
ID: 82f459ad-fb8b-5338-be28-0f66ffc78f22
STIX ID: report--82f459ad-fb8b-5338-be28-0f66ffc78f22
Feed Name: Aqua Security Blog
Aqua Nautilus researchers used honeypots and runtime forensics (Aqua Tracee and Traceeshark) to uncover threat actors exploiting unauthenticated, internet-exposed JupyterLab/Notebook instances to install and run ffmpeg, capture live sports feeds, and re-stream them to external platforms for illicit monetization. The report documents the attack flow, captured commands and artifacts (including an ffmpeg MD5 and attacker IPs), maps techniques to MITRE ATT&CK, and provides detection and mitigation recommendations for securing Jupyter deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
