Threat Alert: Anatomy of Silentbob’s Cloud Attack
ID: c4627b54-2390-581f-813a-1ee1db2221ed
STIX ID: report--c4627b54-2390-581f-813a-1ee1db2221ed
Feed Name: Aqua Security Blog
Aqua Nautilus researchers uncovered an early-stage, worm-like campaign using malicious Docker Hub images that scan for exposed JupyterLab and Docker APIs to deploy Tsunami backdoor, cryptominers, and credential-harvesting scripts; four malicious images (shanidmk/jltest2, jltest, sysapp, blob) were identified and removed from Docker Hub, Shodan revealed ~51 exposed JupyterLab instances with evidence of exploitation, and the behavior and tooling strongly resemble TeamTNT or a sophisticated copycat — the report includes IoCs, code snippets, observed C2 infrastructure, attribution rationale, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
