Prizmant, D. (2021, June 7). Siloscape: First Known Malware Targeting Windows Containers to Compromise Cloud Environments. Retrieved June 9, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareSiloscape | Siloscape itself is obfuscated and uses obfuscated API calls. |
| T1059.003 Windows Command Shell |
MalwareSiloscape | Siloscape can run cmd through an IRC channel. |
| T1068 Exploitation for Privilege Escalation |
MalwareSiloscape | Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host. |
| T1069 Permission Groups Discovery |
MalwareSiloscape | Siloscape checks for Kubernetes node permissions. |
| T1071 Application Layer Protocol |
MalwareSiloscape | Siloscape connects to an IRC server for C2. |
| T1083 File and Directory Discovery |
MalwareSiloscape | Siloscape searches for the Kubernetes config file and other related files using a regular expression. |
| T1090.003 Multi-hop Proxy |
MalwareSiloscape | |
| T1106 Native API |
MalwareSiloscape | Siloscape makes various native API calls. |
| T1134.001 Token Impersonation/Theft |
MalwareSiloscape | Siloscape impersonates the main thread of |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSiloscape | Siloscape has decrypted the password of the C2 server with a simple byte by byte XOR. Siloscape also writes both an archive of Tor and the |
| T1190 Exploit Public-Facing Application |
MalwareSiloscape | Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability. |
| T1518 Software Discovery |
MalwareSiloscape | Siloscape searches for the kubectl binary. |
| T1609 Container Administration Command |
MalwareSiloscape | Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster. |
| T1611 Escape to Host |
MalwareSiloscape | Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.