Fileless Malware Executing in Containers
ID: 9cff674e-ad0f-51ef-8239-6a55b9e1427c
STIX ID: report--9cff674e-ad0f-51ef-8239-6a55b9e1427c
Feed Name: Aqua Security Blog
Team Nautilus researchers identified a TeamTNT campaign on Docker Hub that performs fileless in-memory attacks in containers: malicious images unpack and execute binaries (Tsunami backdoor and a crypto miner) directly from memory, use an LD_PRELOAD rootkit to hide processes (kthreadd), erase host cron jobs to persist, and connect to C2 and mining pool infrastructure; the report includes dynamic detection methodology, multiple IOCs (image names, file hashes, domains/IPs), and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
