Kubernetes Exposed: Exploiting the Kubelet API
ID: e32a7501-ca6d-5cf9-9ed6-c80198694e3b
STIX ID: report--e32a7501-ca6d-5cf9-9ed6-c80198694e3b
Feed Name: Aqua Security Blog
This report describes active attacks against misconfigured Kubernetes Kubelet APIs observed by a honeypot: attackers perform environment discovery and internal scanning, harvest ServiceAccount tokens and configuration files, and deploy a cryptominer (notably via an 'F' gang script and TeamTNT campaigns). The authors measured exposed Kubelet instances via Shodan, found real exploitation cases (including token exfiltration and pod-level command execution), provide an MD5 for the cryptominer, and recommend access restriction, authentication/authorization, monitoring, patching, least-privilege, and automated posture management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
