logo

Threat Alert: Anatomy of Silentbob’s Cloud Attack

ID: c4627b54-2390-581f-813a-1ee1db2221ed

STIX ID: report--c4627b54-2390-581f-813a-1ee1db2221ed

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2023-07-05

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers uncovered an early-stage, worm-like campaign using malicious Docker Hub images that scan for exposed JupyterLab and Docker APIs to deploy Tsunami backdoor, cryptominers, and credential-harvesting scripts; four malicious images (shanidmk/jltest2, jltest, sysapp, blob) were identified and removed from Docker Hub, Shodan revealed ~51 exposed JupyterLab instances with evidence of exploitation, and the behavior and tooling strongly resemble TeamTNT or a sophisticated copycat — the report includes IoCs, code snippets, observed C2 infrastructure, attribution rationale, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.