Skip to content
Business Company News, Information Technology

Aqua Nautilus researchers find Kubernetes clusters under attack in hundreds of organisations

PR Deadlines 3 mins read

Malware and backdoors tech are being used in attacks affecting many Fortune 500 companies.

Aqua Security, the pioneer in cloud native security, today announced a three-month-long investigation by its research team. Aqua Nautilus uncovered that Kubernetes clusters belonging to more than 350 organisations, open-source projects, and individuals, were openly accessible and unprotected.

A notable subset of clusters was connected to vast conglomerates and Fortune 500 companies. At least 60% of these clusters were breached and had an active campaign with deployed malware and backdoors.

The exposures were due to two misconfigurations, emphasising how known and unknown misconfigurations are actively exploited in the wild and can be catastrophic.

“In the wrong hands, access to a company’s Kubernetes cluster could be business ending. Proprietary code, intellectual property, customer data, financial records, access credentials and encryption keys are among the many sensitive assets at risk,” said Assaf Morag, lead threat intelligence analyst at Aqua Nautilus. 

“As Kubernetes has gained immense popularity among businesses in recent years due to its undeniable prowess in orchestrating and managing containerised applications, organisations are entrusting highly sensitive information and tokens in their clusters. This research is a wakeup call about the importance of Kubernetes security.”

In the research, Nautilus highlights a well-known misconfiguration that allows anonymous access with privileges. The second less-known issue was a misconfiguration of the `kubectl` proxy with flags that unknowingly exposed the Kubernetes cluster to the internet.

Impacted hosts included organisations across a variety of sectors, including financial services, aerospace, automotive, industrial and security, among others.

Most concerning were the open source projects and unsuspecting developers who could inadvertently trust and download a malicious package. If compromised, it could trigger a supply chain infection vector with implications for millions of users.

“We analysed many real-world incidents where attackers exploited these misconfigurations to deploy malware, cryptominers, and backdoors,” said Morag.

“Despite the potential risks and tools like Aqua’s software supply chain security suite, misconfigurations continue to persist across organisations of all sizes and industries. Clearly there is a gap in security knowledge and management of Kubernetes. These findings underscore the extensive damage that can result if vulnerabilities are not properly addressed.”

Nautilus contacted the accessible cluster owners they identified, and the responses were also troubling. 

Morag explains: “We were amazed that the initial response was indifference. Many said their clusters ‘are just staging or testing environments.’ However, once we showed them the full potential of an attack from an attacker’s perspective and the potential devastating impact on their organisations, they were all shocked and immediately resolved the issue.

“There is a clear lack of understanding and awareness regarding misconfiguration risks and their impact.”

Ongoing campaigns

Nautilus found that approximately 60% of the clusters were actively under attack by cryptominers and created the first known Kubernetes honeypot environment to collect further data about these attacks to shed light on these ongoing campaigns.

Among the key findings, Nautilus discovered the recently reported novel and highly aggressive Silentbob campaign, revealing the resurgence of TeamTNT targeting Kubernetes clusters. 

Researchers also uncovered a role-based access control (RBAC) Buster campaign to create a hidden backdoor as well as cryptomining campaigns, including a more extensive execution of the previously discovered Dero Campaign with additional container images that cumulatively had hundreds of thousands of pulls.

Nautilus recommends leveraging native Kubernetes features, such as RBAC and admission control policies, to limit privileges and enforce policies that bolster security.

Security teams can also implement regular auditing of Kubernetes clusters to identify anomalies and take quick remedial actions. The Aqua Platform as well as open source tools, such as Aqua Trivy, Aqua Tracee and Kube-Hunter, can be helpful in scanning Kubernetes environments, detecting anomalies and weaknesses, and preventing exploits in real time.

By employing these and other mitigation strategies, organizations can significantly enhance their Kubernetes security, ensuring that their clusters are safe from common attacks. For the full findings and a list of mitigation recommendations, visit Aqua’s blog.

About Aqua Nautilus

Aqua Nautilus focuses on cybersecurity research of the cloud native stack. Its mission is to uncover new vulnerabilities, threats and attacks that target containers, Kubernetes, serverless, and public cloud infrastructure — enabling new methods and tools to address them. With a global network of honeypots, Aqua Nautilus catches more than 80,000 cloud native attacks every month, specifically those unique to containers and microservices that other platforms cannot see.

About Aqua Security

Aqua Security stops cloud native attacks across the application lifecycle and is the only company with a $1M Cloud Native Protection Warranty to guarantee it. As the pioneer in cloud native security, Aqua helps customers reduce risk while building the future of their businesses. The Aqua Platform is the industry’s most integrated Cloud Native Application Protection Platform (CNAPP), protecting the application lifecycle from code to cloud and back. Founded in 2015, Aqua is headquartered

 

in Boston, MA and Ramat Gan, IL with Fortune 1000 customers in over 40 countries. For more information, visit https://www.aquasec.com/.

More from this category

  • Information Technology
  • 29/10/2024
  • 18:41
Cavli Inc

Cavli Wireless Recognized as a Nasscom Emerge 50 Innovator for 2024, Championing ‘Made in India’ Deep Tech Solutions to Drive Global IoT and Wireless Connectivity

Awarded as One of the Nasscom Emerge 50 Companies, Cavli Wireless Continues to Lead the Charge in 'Made in India' IoT and Wireless Technology InnovationBANGALORE, India, Oct. 29, 2024 (GLOBE NEWSWIRE) -- Cavli Wireless, a leading innovator in cellular IoT and wireless connectivity solutions, has been named one of the winners of the esteemed Nasscom Emerge 50 Awards for 2024. This prestigious recognition highlights Cavli's commitment to pioneering "Made in India" technology and deep tech solutions, positioning the company among India's top startups driving innovation in the wireless and IoT space. The Nasscom Emerge 50 Awards spotlight India's most promising…

  • Information Technology
  • 29/10/2024
  • 17:11
OMP

New CEO Commits to Strengthening OMP’s Leadership in Advanced Supply Chain Planning

ANTWERPEN, BELGIUM / ACCESSWIRE / October 29, 2024 / In a leadership transition at the Antwerp-based supply chain specialists, Anita Van Looveren will step into her new role as Chairwoman of the Board of Directors on November 1, after nearly 25 years in the CEO role and almost 40 years with the company. Paul Vanvuchelen, Global Delivery Lead, will succeed her as CEO, beginning a new chapter for OMP with a focus on strengthening its leadership in advanced supply chain planning. In her new position, Anita Van Looveren will continue to work closely with Paul Vanvuchelen, offering strategic guidance and…

  • Agriculture Farming Rural, Business Company News
  • 29/10/2024
  • 12:09
Avocados Australia

Avocados Australia’s latest industry figures out now!

According to Avocados Australia’s latest “Facts at a Glance 2023/24 Report” total Australian avocado production volume is up 30% to 150,913 tonnes when compared with 2022/23’s figure of 115,385 tonnes. Funded by avocado grower levies through Hort Innovation, the report found that the gross value of production (GVP) for Australian avocados is up by 13% to $649 million when compared to $574 million in 2022/23. Export value is up 63% to $96.1 million. Avocados Australia continues to stay focussed on increasing demand in the domestic and export markets and opening up new export markets. The Facts at a Glance 2023/24…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.