VOOZH about

URL: https://thenewstack.io/notorious-malware-cybergang-goes-all-in-on-unsecured-kubernetes-clusters/

⇱ Notorious Malware CyberGang Goes All in on Unsecured Kubernetes Clusters - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-02-05 10:06:34
Notorious Malware CyberGang Goes All in on Unsecured Kubernetes Clusters
news,
Cloud Native Ecosystem / Kubernetes / Security

Notorious Malware CyberGang Goes All in on Unsecured Kubernetes Clusters

TeamTNT, a notorious cybergang known for its container-based attacks on cloud infrastructure, has found Kubernetes to be a useful tool in its efforts to mine Monero cryptocurrency from other people's servers, according to a new report from Unit 42, the research arm of [sponsor_inline_mention slug="prisma" ]Palo Alto Networks[/sponsor_inline_mention].
Feb 5th, 2021 10:06am by Joab Jackson
👁 Featued image for: Notorious Malware CyberGang Goes All in on Unsecured Kubernetes Clusters

TeamTNT, a notorious cybergang known for its container-based attacks on cloud infrastructure, has found Kubernetes to be a useful tool in its efforts to mine Monero cryptocurrency from other people’s servers, according to a new report from Unit 42, the research arm of Palo Alto Networks.

On their own four-node “Honeypot” Kubernetes cluster, the researchers watched the attackers roll out a sophisticated attack that commandeered their containers using common Linux and cloud native tools. The actions were part of a larger botnet, dubbed “Hildegard,” whose size is still undetermined.

“From another ongoing research, we do know that there are at least 2,000 misconfigured Kubernetes clusters,” noted Jay Chen, a Unit 42 senior cloud researcher. These misconfigured systems can be easily found by searching Shodan Internet of Things search engine, and the by search capabilities offered by security vendor Censys. “These misconfigured Kubernetes are all potential targets.”

Being infected by this botnet can be expensive and devastating for end users. “The most significant impact of the malware is resource hijacking and denial of service (DoS). The cryptojacking operation can quickly drain the entire system’s resources and disrupt every application in the cluster, the researchers wrote in their findings report.

Like the other, legitimate uses, of the open source container orchestration engine, Kubernetes brings the attackers heretofore unattainable scalability, given how a Kubernetes cluster can control hundreds or even thousands of containers. The attackers are quickly learning how to exploit this capability too. “This new TeamTNT malware campaign is one of the most complicated attacks targeting Kubernetes,” the researchers  note.

The Tools

The attackers found the honeypot through an unsecured internet-facing Kubelet that allowed anonymous access, through which they pinpointed a container within the cluster and set up shop, using tmate and an IRC to communicate back to headquarters and masscan to scan Kubernetes’ internal network. From there, it was easy to propagate software to other nodes within that cluster.

Malicious processes were hidden under the Linux bioset process name, as well as through a library injection technique built on LD_PRELOAD. Malicious payloads encrypted and tucked into a binary to avert detection by static analysis.

👁 Image

Impact

This is not the first cloud native tool the gang has deployed. Last year, Microsoft researchers observed TeamTNT download and run Weave Scope in cracked containers, to get a layout of the victim’s infrastructure, Threat Post reported. Last August, the Unit42 researchers also documented Cetus, a Docker-based Docker cryptojacking worm they allege was created by TeamTnT (not to be confused with the TeamTnT collective entity known creating add-on episodes of the Doom computer game). This shadowy entity also allegedly created Black-T, which targets credential files on Amazon Web Services, as well as the IRC bot, TeamTNT DDoS.

This new botnet seems to be quiet of late — no updates have been made since the researchers discovered it in early January.

“There has not been any activity since our initial detection, which indicates the threat campaign may still be in the reconnaissance and weaponization stage,” the researchers report. Nonetheless, the botnet on this honeypot cluster tapped into ~25.05 KH/s hashing power and has harvested 11 XMR (~$1,500) of Monero digital currency.

Palo Alto Networks also would like to remind everyone that customers running Prisma Cloud are protected from this threat, through the software’s Runtime Protection feature.

The report offers a full rundown on the techniques and technologies used to infiltrate cluster, and the impact these actions have on the infected system.

Palo Alto Networks is a sponsor of The New Stack.

Feature image: New Old Stock.

TRENDING STORIES
Joab Jackson is a senior editor for The New Stack, covering cloud native computing and system operations. He has reported on IT infrastructure and development for over 30 years, including stints at IDG and Government Computer News. Before that, he...
Read more from Joab Jackson
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Docker, Unit.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.