logo

Advanced Persistent Threat Techniques Used in Container Attacks

ID: cda02514-7969-5221-9c36-933bcb501a08

STIX ID: report--cda02514-7969-5221-9c36-933bcb501a08

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2021-08-26

Date Updated: 2026-05-12

...
...

This report analyzes an active campaign targeting cloud-native hosts in which attackers run vanilla containers, escape to the host by mounting the filesystem, deploy a cron-based payload (cronb.sh), and install either the Diamorphine kernel rootkit or a user-space rootkit to hide processes (including an XMRig cryptominer) and maintain persistence. The analysis details Diamorphine's syscall hooking and DKOM techniques, the attackers' fallback to user-space binary replacement, observed attack volumes, and recommended mitigations such as kernel updates, signed modules, Tracee monitoring, and file integrity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.