logo

Stopping Sobolan Malware with Aqua Runtime Protection

ID: cb35d9e0-91e8-5e5e-9e8d-2b40fe433ad0

STIX ID: report--cb35d9e0-91e8-5e5e-9e8d-2b40fe433ad0

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-04-26

...
...

Aqua Nautilus discovered the Sobolan campaign exploiting unauthenticated Jupyter-like notebook environments: attackers download a tar from 167.172.154.218 that deploys 13 malicious files (shell scripts and binaries) under /var/tmp to establish persistence, run cryptominers (syst3md, sobolan, pythonlol), kill competing processes, and attempt stealthy communications; Aqua Runtime Protection detected and blocked many events and provides IOCs (IP addresses and MD5 hashes) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.