logo

First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters

ID: d5db9867-2bee-5f42-a706-535104cd3b67

STIX ID: report--d5db9867-2bee-5f42-a706-535104cd3b67

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2023-04-21

Date Updated: 2026-04-26

...
...

This report documents 'RBAC Buster', an active in-the-wild campaign that abuses misconfigured Kubernetes API servers and RBAC to create persistent ClusterRoleBindings and ServiceAccounts, then deploys a typosquatted DaemonSet image (kuberntesio/kube-controller) containing a Monero cryptominer; researchers linked the activity to at least 60 compromised clusters, observed use of exposed AWS keys to pivot, and provide IOCs and mitigation recommendations (secure API authentication, scan for misconfigurations and exposed secrets, use tools like Trivy/CNAPP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.