Cloud-y Linux Malware Rains on Apache, Docker, Redis & Confluence
"Spinning YARN" cyberattackers wielding a Linux webshell are positioning for broader cloud compromise by exploiting common misconfigurations and a known Atlassian Confluence bug.
Researchers have spotted a concerted cyber compromise campaign targeting cloud servers running vulnerable instances of Apache Hadoop, Atlassian Confluence, Docker, and Redis. The attackers are dropping a cryptomining tool, but also installing a Linux-based reverse shell that would allow potential future targeting and malware infestations.
According to an analysis from Cado Security, in most cases the adversary is hunting for common cloud misconfigurations to exploit. But, it has also been using an older remote code execution (RCE) vulnerability in Confluence server (CVE-2022-26134) in its ongoing campaign.
The researchers also said the attackers' tactics overlap with TeamTNT and WatchDog, two threat groups known for targeting cloud and container environments.
"The attacks are relatively hard-coded and automated, so they look for known vulnerabilities in Confluence and other platforms and well-known misconfigurations in platforms like Redis and Docker," says Chris Doman, co-founder and CTO at Cado Security.
Identifying these vulnerable instances is often simple, based on scanning as a first step and attacking identified vulnerable instances as a second step.
About the Author
You May Also Like