First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters
ID: d5db9867-2bee-5f42-a706-535104cd3b67
STIX ID: report--d5db9867-2bee-5f42-a706-535104cd3b67
Feed Name: Aqua Security Blog
This report documents 'RBAC Buster', an active in-the-wild campaign that abuses misconfigured Kubernetes API servers and RBAC to create persistent ClusterRoleBindings and ServiceAccounts, then deploys a typosquatted DaemonSet image (kuberntesio/kube-controller) containing a Monero cryptominer; researchers linked the activity to at least 60 compromised clusters, observed use of exposed AWS keys to pivot, and provide IOCs and mitigation recommendations (secure API authentication, scan for misconfigurations and exposed secrets, use tools like Trivy/CNAPP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
