Market-First Container Image Built to Attack Kubernetes Cluste
ID: afdfbe22-3111-53fb-a4b4-0bee70284220
STIX ID: report--afdfbe22-3111-53fb-a4b4-0bee70284220
Feed Name: Aqua Security Blog
Threat Score
Aqua’s Team Nautilus uncovered a TeamTNT campaign using a typosquatted Docker Hub account (portaienr) to distribute malicious container images that run offensive security tools (e.g., DEEPCE, kube-hunter, bob, ed) to enumerate and escape containers, exploit Kubernetes misconfigurations, steal credentials, and deploy miners/backdoors; the report includes detailed file MD5s, domains, IOCs, an OSINT-verified victim report, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
