Container Administration Command

T1609

Technique.View on attack.mitre.org

About this technique

Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.

In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as docker exec to execute a command within a running container. In Kubernetes, if an adversary has sufficient permissions, they may gain remote execution in a container in the cluster via interaction with the Kubernetes API server, the kubelet, or by running a command such as kubectl exec.

Detection rules3

Rules on DetectionCode tagged with T1609.

Sigma3

RuleLevelLog source
Kubernetes Potential Enumeration Activitymediumkubernetes / NULL
Potential Remote Command Execution In Pod Containermediumkubernetes / application
Potential Sidecar Injection Into Running Deploymentmediumkubernetes / application

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software7

Campaigns0

None recorded.

Procedure examples8

Groups1

Used byProcedure example
GroupTeamTNT

TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers.

Software7

Used byProcedure example
MalwareCanisterWorm

CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.

MalwareHildegard

Hildegard was executed through the kubelet API run command and by executing commands on running containers.

MalwareKinsing

Kinsing was executed with an Ubuntu container entry point that runs shell scripts.

MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.

ToolPeirates

Peirates can use `kubectl` or the Kubernetes API to run commands.

MalwareSiloscape

Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes.

References6

  1. Docker Daemon CLI Open source
    Docker. (n.d.). DockerD CLI. Retrieved March 29, 2021.
  2. Docker Entrypoint Open source
    Docker. (n.d.). Docker run reference. Retrieved March 29, 2021.
  3. Docker Exec Open source
    Docker. (n.d.). Docker Exec. Retrieved March 29, 2021.
  4. Kubectl Exec Get Shell Open source
    The Kubernetes Authors. (n.d.). Get a Shell to a Running Container. Retrieved March 29, 2021.
  5. Kubernetes API Open source
    The Kubernetes Authors. (n.d.). The Kubernetes API. Retrieved March 29, 2021.
  6. Kubernetes Kubelet Open source
    The Kubernetes Authors. (n.d.). Kubelet. Retrieved March 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.