PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer
ID: f99aabe7-3817-5a8d-9ac5-1c25a15d48d8
STIX ID: report--f99aabe7-3817-5a8d-9ac5-1c25a15d48d8
Feed Name: Wiz Blog
Threat Score
The report details “PyLoose,” a Python-based fileless cryptomining campaign that loads a precompiled XMRig miner directly into memory using Linux memfd (reflective execution) via exposed Jupyter Notebook services; it documents ~200 observed instances, provides full technical analysis of the loader and execution flow, lists IoCs (hashes, IPs, domains, wallet), maps MITRE techniques, and offers detection and mitigation guidance for cloud workloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
