logo

Fileless Malware Executing in Containers

ID: 9cff674e-ad0f-51ef-8239-6a55b9e1427c

STIX ID: report--9cff674e-ad0f-51ef-8239-6a55b9e1427c

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-12-02

Date Updated: 2026-04-26

...
...

Team Nautilus researchers identified a TeamTNT campaign on Docker Hub that performs fileless in-memory attacks in containers: malicious images unpack and execute binaries (Tsunami backdoor and a crypto miner) directly from memory, use an LD_PRELOAD rootkit to hide processes (kthreadd), erase host cron jobs to persist, and connect to C2 and mining pool infrastructure; the report includes dynamic detection methodology, multiple IOCs (image names, file hashes, domains/IPs), and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.