Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

April 21, 2023Rabbi LakshmananKubernetes / cryptocurrency

Kubernetes RBAC

Large-scale attack campaigns have been discovered that exploit Kubernetes (K8s) role-based access control (RBAC) to create backdoors and run cryptocurrency miners.

“The attackers also deployed a DaemonSet to hijack and hijack the resources of the K8s clusters they attacked,” said cloud security firm Aqua in a report shared with The Hacker News.Israeli company that dubbed the attack RBAC Bustersaid it found 60 exposed K8s clusters exploited by the threat actors behind this campaign.

The attack chain begins with the attacker gaining initial access through a misconfigured API server, then checks the compromised server for evidence of competing minor malware, and uses RBAC to persist. set gender.

“The attacker created a new ClusterRole with almost administrator-level privileges,” the company said. “The attacker then created ‘ServiceAccount’, ‘kube-controller’ in the ‘kube-system’ namespace. Finally, the attacker created a ‘ClusterRoleBinding’ and bound the ClusterRole to her ServiceAccount. created a strong, discreet permanence.”

In an observed intrusion into a K8s honeypot, attackers weaponized exposed AWS access keys, gained a foothold in environments, stole data, and attempted to escape cluster boundaries.

Kubernetes RBAC

The final step in the attack required the threat actor to create a DaemonSet to deploy a Docker-hosted container image (“kuberntesio/kube-controller:1.0.1”) to all nodes. A container that has been pulled by him 14,399 times since it was uploaded five months ago harbors a cryptocurrency miner.

upcoming webinars

Zero Trust + Deception: Learn How to Outsmart Attackers!

See how Deception can detect advanced threats, stop lateral movement, and strengthen your Zero Trust strategy. Join us for an insightful webinar!

Save my seat!

“The container image named ‘kuberntesio/kube-controller’ is an example of typosquatting that masquerades as a legitimate ‘kubernetesio’ account,” said Aqua. “This image also mimics the popular ‘kube-controller-manager’ container he image. It is a key component of the control plane, running inside his Pods on every master node and responsible for detecting and responding to node failures. “

Interestingly, some of the tactics described in the campaign are similar to another illegal cryptocurrency mining operation that also utilized DaemonSets to create Dero and Monero. It is not clear at this time if the two sets of attacks are related.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *