• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Wednesday, July 9, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Rootkit Turns Kubernetes From Orchestration to Subversion

22 November 2023
in Mining
Reading Time: 4 mins read
A A
0
Rootkit Turns Kubernetes From Orchestration to Subversion
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

As software development focuses on continuous integration and deployment, orchestration platforms like Kubernetes have taken off, but that popularity has put them in attackers’ crosshairs.

Most successful attacks — at least those publicly reported — have led to the deployment of cryptomining-focused containers, basically stealing cloud compute resources from businesses to power cryptocurrency mining. Yet the attacks could be much worse — infecting Kubernetes clusters with rootkits would result in collections of containers controlled by attackers, says Nicholas Lang, a security researcher with cloud-infrastructure security firm Sysdig, who will present a prototype rootkit at Black Hat Europe next month.

The successful compromise of a Kubernetes cluster by a rootkit could allow an attacker to hide malicious containers on the system, for example. The rootkit can hide other containerized payloads and take more sophisticated actions escaping notice in the system, because they are hidden from the operating system, he says.

“Even though it interacts with the kernel to get these containers up and in place, after that … the rootkit is able to hide these containerized payloads,” Lang says. “The rootkit is part of the initial payload … and then, you know, future stages will do more sophisticated things in secret because they’re hidden from the operating system by the rootkit.”

Kubernetes is a popular way of automating the configuration, deployment, and management — that is, “orchestration” — of containers, virtualized software environments that can run a wide variety of workloads, from servers to applications to software-defined networks. As such, the technology is critical for cloud applications in today’s fast-moving world of software development and deployment.

Vulnerabilities and misconfigurations are top concerns for Kubernetes. Source: Red Hat

For the same reason, however, attackers have targeted the infrastructure. In February, an attacker compromised a misconfigured Kubernetes cluster, first installing cryptojacking containers and then stealing intellectual property and sensitive data. A month earlier, Microsoft researchers discovered that the Kinsing malware had started targeting poorly configured database containers on Kubernetes platforms.

Kubernetes Under Attack

The spate of attacks have software firms worried. Two-thirds of companies (67%) have delayed or slowed down an application deployment due to a security concern with Kubernetes, according to Red Hat’s “2023 State of Kubernetes Security Report.”

While attackers have exploited vulnerabilities in Kubernetes infrastructure, misconfigured applications running in containers are, by far, the most common way that the orchestration platform is compromised, says Sysdig’s Lang.

“A misconfigured Web server or Web application gives the attacker shell access to that virtual machine or inside that container,” he says. “Depending on the attacker’s sophistication level, they’ll either realize that they’re inside of a container or a virtual machine, or whatever, and try to escape to the host, or they realize that they’re in a Kubernetes environment by doing a little bit of poking and prodding.”

While a specific Linux kernel rootkit, known as Diamorphine, has occasionally been used to compromise Kubernetes clusters, Kubernetes-focused rootkits have not yet become popular.

Lang argues that will change, and as a view into the future, he and another security researcher, Andrew Hughes of Narf Industries, plan to demonstrate their own Kubernetes rootkit at the Black Hat Europe Conference in December. “The real change is the attackers learning that Kubernetes is increasingly common in the cloud, and how to deal with it and how to get around it, and how to make use of it even,” he says.

Kubernetes Admins Need Visibility

Typically, a victim would have to see a rootkit getting loaded or a vulnerability being exploited by the attacker to catch an attack on a Kubernetes cluster, Lang says. However, admins can also look out for kernel modules that get loaded during runtime, which really should not happen in a production setting, he says.

“These systems don’t really do a whole lot of crazy stuff, so if you see [kernel modules loading] inside a container or on host that runs containers, you can be pretty confident something bad is going on,” he says. “Otherwise, catching it is very, very difficult, because a lot of it happens in user space or in an application layer where you don’t have a lot of deep insight.”

Admins should also ask their red team to conduct a group exercise, working against defenders to attack, and then with defenders to analyze the attack — a process referred to as purple teaming.

Sysdig runs its own honeypot, exposing Kubernetes ports to potential attacks, and typically, the first probes come quickly, Lang says.

“Within minutes, sometimes seconds, it’s already getting attacked,” he says. “So purple teaming is how you will find and close your gaps, and then not putting Kubernetes on the Internet in the first place is a great way to not get attacked.”

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: KubernetesOrchestrationRootkitSubversionTurns
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Imaging quantum oscillations and millitesla pseudomagnetic fields in graphene

Next Post

What Does CoinGecko’s Zash Acquisition Mean For NFT Market?

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
What Does CoinGecko’s Zash Acquisition Mean For NFT Market?

What Does CoinGecko's Zash Acquisition Mean For NFT Market?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
RWA, BNB News: Kraken, Backed Expand Tokenized Stocks to BNB Chain – CoinDesk

RWA, BNB News: Kraken, Backed Expand Tokenized Stocks to BNB Chain – CoinDesk

9 July 2025
POL (prev. MATIC) Breaks Out: Is It Time to Go Long?

POL (prev. MATIC) Breaks Out: Is It Time to Go Long?

9 July 2025
XRP News Today: Little Pepe (LILPEPE) Presale Raises .6 Million, Outperforming Solana, Ethereum, XRP – AInvest

XRP News Today: Little Pepe (LILPEPE) Presale Raises $3.6 Million, Outperforming Solana, Ethereum, XRP – AInvest

9 July 2025
Analyst Predicts Bitcoin Price Breakdown — Here’s The Best Time To Buy

Analyst Predicts Bitcoin Price Breakdown — Here’s The Best Time To Buy

9 July 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • RWA, BNB News: Kraken, Backed Expand Tokenized Stocks to BNB Chain – CoinDesk
  • POL (prev. MATIC) Breaks Out: Is It Time to Go Long?
  • XRP News Today: Little Pepe (LILPEPE) Presale Raises $3.6 Million, Outperforming Solana, Ethereum, XRP – AInvest
  • Analyst Predicts Bitcoin Price Breakdown — Here’s The Best Time To Buy
  • Whales Scoop Up 200,000 ETH

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 109,468.00
  • ethereumEthereum (ETH) $ 2,657.18
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.39
  • bnbBNB (BNB) $ 662.10
  • solanaSolana (SOL) $ 154.29
  • usd-coinUSDC (USDC) $ 0.999899
  • tronTRON (TRX) $ 0.287567
  • dogecoinDogecoin (DOGE) $ 0.174478
  • staked-etherLido Staked Ether (STETH) $ 2,657.08
  • cardanoCardano (ADA) $ 0.614126
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 109,375.00
  • hyperliquidHyperliquid (HYPE) $ 39.47
  • wrapped-stethWrapped stETH (WSTETH) $ 3,202.20
  • suiSui (SUI) $ 2.96
  • bitcoin-cashBitcoin Cash (BCH) $ 508.45
  • chainlinkChainlink (LINK) $ 14.11
  • stellarStellar (XLM) $ 0.283079
  • leo-tokenLEO Token (LEO) $ 9.01
  • avalanche-2Avalanche (AVAX) $ 18.68
  • usdsUSDS (USDS) $ 0.999764
  • hedera-hashgraphHedera (HBAR) $ 0.170716
  • wrapped-eethWrapped eETH (WEETH) $ 2,844.91
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • the-open-networkToncoin (TON) $ 2.83
  • wethWETH (WETH) $ 2,655.02
  • litecoinLitecoin (LTC) $ 88.72
  • whitebitWhiteBIT Coin (WBT) $ 45.17
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • moneroMonero (XMR) $ 320.78
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 109,359.00
  • polkadotPolkadot (DOT) $ 3.54
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 4.36
  • uniswapUniswap (UNI) $ 8.17
  • aaveAave (AAVE) $ 301.28
  • pepePepe (PEPE) $ 0.000010
  • daiDai (DAI) $ 0.999965
  • pi-networkPi Network (PI) $ 0.466203
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • bittensorBittensor (TAO) $ 329.13
  • crypto-com-chainCronos (CRO) $ 0.094687
  • aptosAptos (APT) $ 4.57
  • okbOKB (OKB) $ 48.50
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.29
  • jito-staked-solJito Staked SOL (JITOSOL) $ 187.53
  • internet-computerInternet Computer (ICP) $ 4.97
  • ethereum-classicEthereum Classic (ETC) $ 17.28
  • ondo-financeOndo (ONDO) $ 0.819041