logo

Market-First Container Image Built to Attack Kubernetes Cluste

ID: afdfbe22-3111-53fb-a4b4-0bee70284220

STIX ID: report--afdfbe22-3111-53fb-a4b4-0bee70284220

Feed Name: Aqua Security Blog

Threat Score
78/100

Date Published: 2020-11-23

Date Updated: 2026-04-26

...
...

Aqua’s Team Nautilus uncovered a TeamTNT campaign using a typosquatted Docker Hub account (portaienr) to distribute malicious container images that run offensive security tools (e.g., DEEPCE, kube-hunter, bob, ed) to enumerate and escape containers, exploit Kubernetes misconfigurations, steal credentials, and deploy miners/backdoors; the report includes detailed file MD5s, domains, IOCs, an OSINT-verified victim report, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.