Silentbob Campaign: Cloud-Native Environments Under Attack

July 6, 2023Ravi LakshmananCloud security/server hacking

silent bob campaign

Cybersecurity researchers have discovered attack infrastructure being used as part of a “potentially large-scale campaign” against cloud-native environments.

“This infrastructure is in the early stages of testing and deployment and is primarily consistent with aggressive cloud worms, and has been exposed to the public to deploy Tsunami malware, cloud credential hijacking, resource hijacking, and further infections. It’s a worm designed to deploy on a well-designed JupyterLab and Docker API,” said cloud security firm Aqua.

called an activity silent bob It references an AnonDNS domain set by the attackers and is said to be associated with the notorious cryptojacking group tracked as TeamTNT, citing overlapping tactics, techniques and procedures (TTPs). However, the involvement of “advanced imitators” is not ruled out.

Aqua’s investigation began in early June 2023 in the aftermath of an attack targeting its honeypots, which resulted in the detection of exposed Docker and Jupyter Lab instances, a cryptocurrency miner and a Tsunami backdoor. We discovered four malicious container images designed to be deployed.

This feat is accomplished by a shell script programmed to run on container startup and used to deploy a Go-based ZGrab scanner to find misconfigured servers. Docker has since removed the image from the public registry. The list of images is below –

  • shanidmk/jltest2 (44 pulls)
  • shanidmk/jltest (8 pulls)
  • shanidmk/sysapp (11 pulls)
  • shanidmk/blob (29 pulls)

In addition to running a cryptocurrency miner on the infected host, shanidmk/sysapp is configured to download and execute additional binaries, which Aqua said could be either a backup cryptominer or the Tsunami malware. It is said that there is a possibility that it is either

upcoming webinars

🔐 Privileged Access Management: Learn How to Overcome Key Challenges

Discover different approaches to overcoming the challenges of privileged account management (PAM) and leveling up your privileged access security strategy.

reserve a spot

The container also downloads a file named “aws.sh.txt”. This script is designed to systematically scan his environment for AWS keys, presumably for subsequent leaks.

Aqua said it found 51 servers with exposed JupyterLab instances, all of which were either actively exploited or showing signs of exploitation by threat actors. This includes “a live manual attack against one of his servers using Masscan to scan for exposed Docker APIs.”

According to security researchers Ofek Itach and Assaf Morag, “Attackers first identify a misconfigured server (either the Docker API or JupyterLab) and then deploy a container or use the command line interface (CLI). to scan and identify additional victims.”

“This process is designed to spread the malware to more servers. The secondary payload of this attack included a cryptocurrency miner and a backdoor, the latter of which used the Tsunami malware as a weapon. I have.”

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *