logo

Intro to Fileless Malware in Containers

ID: babbddb6-7c16-5217-a7ed-e457d36eb3d6

STIX ID: report--babbddb6-7c16-5217-a7ed-e457d36eb3d6

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-08-11

Date Updated: 2026-04-26

...
...

This report explains fileless malware targeting Linux and container environments, detailing how attackers can use techniques such as memfd_create, ptrace, and LD_PRELOAD to inject and execute ELF binaries directly in memory (demonstrated via a memrun demo), and demonstrates detection approaches using Tracee and Aqua CNDR along with recommendations for vulnerability scanning and runtime behavioral monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.