Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Siloscape itself is obfuscated and uses obfuscated API calls. |
| T1059.003 Windows Command Shell |
Siloscape can run cmd through an IRC channel. |
| T1068 Exploitation for Privilege Escalation |
Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host. |
| T1069 Permission Groups Discovery |
Siloscape checks for Kubernetes node permissions. |
| T1071 Application Layer Protocol |
Siloscape connects to an IRC server for C2. |
| T1083 File and Directory Discovery |
Siloscape searches for the Kubernetes config file and other related files using a regular expression. |
| T1090.003 Multi-hop Proxy |
|
| T1106 Native API |
Siloscape makes various native API calls. |
| T1134.001 Token Impersonation/Theft |
Siloscape impersonates the main thread of |
| T1140 Deobfuscate/Decode Files or Information |
Siloscape has decrypted the password of the C2 server with a simple byte by byte XOR. Siloscape also writes both an archive of Tor and the |
| T1190 Exploit Public-Facing Application |
Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability. |
| T1518 Software Discovery |
Siloscape searches for the kubectl binary. |
| T1609 Container Administration Command |
Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster. |
| T1611 Escape to Host |
Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.