New Malware Targets Windows Containers, Kubernetes Clusters

Share post:

A new malware, which has been active for more than a year, causes Windows containers to compromise Kubernetes clusters, with the aim of backdooring them and paving the way for attackers to exploit them.

Kubernetes was originally developed by Google and is currently maintained by the Cloud Native Computing Foundation, an open-source system that helps deploy, scale, and manage containerized workloads, services, and apps through clusters of hosts.

Siloscape, the new malware from Unit 42 security researcher Daniel Prizmant, is the first malware to target Windows containers. It exploits known vulnerabilities affecting web servers and databases with the aim of compromising Kubernetes and backdooring clusters.

Siloscape uses various container escape tactics to execute code on the underlying Kubernetes node. Compromised nodes are then scanned for credentials that allow malware to spread to other nodes in the Kubernetes cluster.

The Siloscape malware also establishes communication channels with its command-and-control server via IRC via the anonymous Tor communication network and listens for incoming commands from its masters.

After gaining access to the malware’s C2 server, Prizmant was able to identify 23 victims and found that the server housed a total of 313 users, suggesting that Siloscape is only a tiny part of a larger campaign.

Siloscape circumvents detection by avoiding actions that could alert the owners of the compromised clusters about the attack, including cryptojacking.

Once the Kubernetes clusters have been backdoored, it opens the way for attackers to exploit compromised cloud infrastructure for more malicious purposes such as theft of login credentials, data exfiltration, ransomware attacks and supply chain attacks.

Kubernetes administrators are asked to switch from Windows containers to Hyper-V containers and ensure that their cluster is securely configured to prevent malware such as Siloscape from using malicious containers.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

Synology Vulnerability Allows Remote Code Execution

A major security flaw in Synology's DiskStation Manager (DSM) software could allow remote attackers to take full control...

New Browser-in-the-Middle Attack Bypasses MFA, Steals User Sessions in Seconds

A sophisticated cyberattack technique known as Browser-in-the-Middle (BitM) has emerged, enabling hackers to bypass multi-factor authentication (MFA) and...

Oracle Cloud Hit By Biggest Supply Chain Attack of 2025 – 140,000 Businesses At Risk

A significant security breach has compromised Oracle Cloud's infrastructure, exposing approximately 6 million records and placing over 140,000...

CISA Red Team Terminations Raise Concern Over U.S. Cybersecurity

Recent operational upheavals within the Cybersecurity and Infrastructure Security Agency's (CISA) Red Team are prompting serious concerns about...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways