Cloud Network Bandwidth Now Stolen through Cryptojacking
ID: f515d7c5-7c8d-57f8-9c01-5ae5eef29671
STIX ID: report--f515d7c5-7c8d-57f8-9c01-5ae5eef29671
Feed Name: Aqua Security Blog
Threat Score
This report analyzes a novel cryptojacking campaign that uses PacketCrypt/PKT Cash to monetize stolen network bandwidth (instead of heavy CPU mining), documents multiple actor clusters and thousands of suspicious GitHub repositories, demonstrates use of rootkits and container-based evasion, shows abuse of free-tier platforms (notably Heroku and CI services), and provides indicators and MITRE ATT&CK mappings for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
