Advanced Persistent Threat Techniques Used in Container Attacks
ID: cda02514-7969-5221-9c36-933bcb501a08
STIX ID: report--cda02514-7969-5221-9c36-933bcb501a08
Feed Name: Aqua Security Blog
This report analyzes an active campaign targeting cloud-native hosts in which attackers run vanilla containers, escape to the host by mounting the filesystem, deploy a cron-based payload (cronb.sh), and install either the Diamorphine kernel rootkit or a user-space rootkit to hide processes (including an XMRig cryptominer) and maintain persistence. The analysis details Diamorphine's syscall hooking and DKOM techniques, the attackers' fallback to user-space binary replacement, observed attack volumes, and recommended mitigations such as kernel updates, signed modules, Tracee monitoring, and file integrity monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
