ATT&CKReferencesUnit 42 Siloscape Jun 2021

Unit 42 Siloscape Jun 2021

Prizmant, D. (2021, June 7). Siloscape: First Known Malware Targeting Windows Containers to Compromise Cloud Environments. Retrieved June 9, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareSiloscape

Siloscape itself is obfuscated and uses obfuscated API calls.

T1059.003
Windows Command Shell
MalwareSiloscape

Siloscape can run cmd through an IRC channel.

T1068
Exploitation for Privilege Escalation
MalwareSiloscape

Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host.

T1069
Permission Groups Discovery
MalwareSiloscape

Siloscape checks for Kubernetes node permissions.

T1071
Application Layer Protocol
MalwareSiloscape

Siloscape connects to an IRC server for C2.

T1083
File and Directory Discovery
MalwareSiloscape

Siloscape searches for the Kubernetes config file and other related files using a regular expression.

T1090.003
Multi-hop Proxy
MalwareSiloscape

Siloscape uses Tor to communicate with C2.

T1106
Native API
MalwareSiloscape

Siloscape makes various native API calls.

T1134.001
Token Impersonation/Theft
MalwareSiloscape

Siloscape impersonates the main thread of CExecSvc.exe by calling NtImpersonateThread.

T1140
Deobfuscate/Decode Files or Information
MalwareSiloscape

Siloscape has decrypted the password of the C2 server with a simple byte by byte XOR. Siloscape also writes both an archive of Tor and the unzip binary to disk from data embedded within the payload using Visual Studio’s Resource Manager.

T1190
Exploit Public-Facing Application
MalwareSiloscape

Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability.

T1518
Software Discovery
MalwareSiloscape

Siloscape searches for the kubectl binary.

T1609
Container Administration Command
MalwareSiloscape

Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster.

T1611
Escape to Host
MalwareSiloscape

Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of NtSetInformationSymbolicLink.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.