• bitcoinBitcoin(BTC)$78,692.000.04%
  • ethereumEthereum(ETH)$2,494.260.04%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$740.20-1.94%
  • rippleXRP(XRP)$1.42-0.73%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$103.23-0.75%
  • tronTRON(TRX)$0.3399300.16%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-2.78%
  • zcashZcash(ZEC)$1,282.157.34%
  • HyperliquidHyperliquid(HYPE)$85.341.52%
  • dogecoinDogecoin(DOGE)$0.089028-1.28%
  • RainRain(RAIN)$0.016318-2.17%
  • USDSUSDS(USDS)$1.00-0.01%
  • whitebitWhiteBIT Coin(WBT)$81.36-0.31%
  • moneroMonero(XMR)$505.531.09%
  • chainlinkChainlink(LINK)$12.00-5.31%
  • leo-tokenLEO Token(LEO)$9.18-0.15%
  • cardanoCardano(ADA)$0.216466-4.85%
  • stellarStellar(XLM)$0.184655-3.54%
  • bitcoin-cashBitcoin Cash(BCH)$257.42-0.08%
  • daiDai(DAI)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • USD1USD1(USD1)$1.00-0.02%
  • litecoinLitecoin(LTC)$54.07-0.58%
  • CantonCanton(CC)$0.104363-0.89%
  • uniswapUniswap(UNI)$6.53-4.56%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.39-1.45%
  • avalanche-2Avalanche(AVAX)$7.93-1.42%
  • hedera-hashgraphHedera(HBAR)$0.078093-2.78%
  • nearNEAR Protocol(NEAR)$2.608.95%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • suiSui(SUI)$0.79-3.40%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.93%
  • crypto-com-chainCronos(CRO)$0.059499-1.20%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,398.580.14%
  • MemeCoreMemeCore(M)$1.17-1.98%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • BittensorBittensor(TAO)$257.59-3.20%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • okbOKB(OKB)$113.06-1.25%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.15-0.04%
  • mantleMantle(MNT)$0.63-0.71%
  • AsterAster(ASTER)$0.74-2.46%
  • aaveAave(AAVE)$129.42-0.46%
  • Pump.funPump.fun(PUMP)$0.0047408.90%
  • polkadotPolkadot(DOT)$1.13-4.75%
  • pax-goldPAX Gold(PAXG)$4,401.420.16%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Protecting against new Kubernetes threats in 2024 and beyond

December 10, 2023
in AI & Technology
Reading Time: 6 mins read
A A
Protecting against new Kubernetes threats in 2024 and beyond
ShareShareShareShareShare

Are you ready to bring more awareness to your brand? Consider becoming a sponsor for The AI Impact Tour. Learn more about the opportunities here.


A wave of new attacks targeted Kubernetes in 2023: Dero and Monero crypto miners, Scarleteel and RBAC-Buster. Finding an initial foothold with a web app vulnerability, then moving laterally is the hallmark of a Kubernetes attack. Understanding the reality of these attacks can help protect your organization from current and future attacks targeting Kubernetes.

YOU MAY ALSO LIKE

Why It’s Time to Abandon the ‘Set It and Forget It’ Model – Unite.AI

Lyft Is Now Offering Waymo Rides In Nashville

Here’s a breakdown of how the attacks unfold and what you can do to protect against them — or at least minimize the damage once attacked.

Scarleteel plan of attack

A Jupyter notebook web application hosted in Kubernetes was the entry point for Scarleteel, with the goal of accessing encrypted, sensitive data housed in cloud storage and crypto mining. To find open entry to the AWS cloud environment, the attackers also used an open-source Kubernetes penetration testing tool called Peirates, along with a similar tool called Pacu.

Scarleteel demonstrated how fluidly an attacker can move through a cloud environment. The attacker jumped from a web application hosted in Kubernetes straight to the cloud to Kubernetes and then back again. Defenders do not have a similarly connected view of their environment, instead looking at cloud security, web app security and Kubernetes security separately, then struggling to put together the full motion and objectives of the attacker. 

VB Event

The AI Impact Tour

Connect with the enterprise AI community at VentureBeat’s AI Impact Tour coming to a city near you!

 

Learn More

What you can do to protect from Scarleteel

If you’re not using Jupyter notebooks, you might not be susceptible to this attack. But there are many other web app vulnerabilities. You can ensure that you protect against the very specific cloud misconfiguration the attackers took advantage of. If you run EKS, look into places where you have IMDSv1 versus IMDSv2 installed and get a blue team to run Peirates and Paco against your environment before an attacker does.

Runtime capabilities would potentially detect the Pandora malware, but wouldn’t connect this to the broader attack and activity happening across the cloud and Kubernetes environments, so it can’t stop the entirety of the attack.

Dero and Monero Cryptocurrency Miners

In the Dero attack, the bad actor first scanned for Kubernetes APIs where authentication is set to allow anyone anonymous access. For this to work, the cluster also needed RBAC configuration that allowed for the creation of pods in that cluster. With these conditions met, the attacker deployed a Daemonset, creating its own pods from malicious images across the cluster. 

The first part of the Monero attack is the same as Dero. Then, with access to the Kubernetes API, attackers deleted the Dero pods and deployed their own privileged pod via Daemonset. The privileged pod then attempted to mount the host directory to escape the container and downloaded a rootkit that could hide the miner. Afterward, the attacker installed a custom mining service on the host.

Unlike Dero, the Monero attack involves privilege escalation and container escape techniques. Allowing privileged containers is one of the most critical Kubernetes security issues to avoid. Kubernetes disallows privileged pods in its baseline policy for Pod Security Standards, making it less likely this will happen by default.

However, if you’re running EKS and Kubernetes v1.13 and above, the default pod security policy is privileged. In EKS, you must delete this policy to enable your customer policies — an added step that potentially increases the chances you’ll allow creation of privileged pods. 

In Monero, there’s a lot of runtime activity that happens after hackers take advantage of the initial Kubernetes misconfiguration. Locking this down would prevent malicious runtime behavior from spreading to other pods and clusters. Stopping disallowed host mounted paths and privileged pod misconfigurations is the most important preventive measure. If you’re doing KSPM on polling intervals, you’re missing any attacker activity that happens in between.

How to protect from the Dero / Monero attacks

If exposed, your primary concern is tamping down the blast radius — as the attack occurs in real-time in Kubernetes, not in runtime. If your runtime capability includes a rule around Monero crypto mining, you can stop the last step but not the initial phases of the compromise.

Although you probably wouldn’t set your API to allow anonymous access, there are other ways this same entry point could be exploited. A malicious insider may plant backdoors or cryptocurrency miners similar to the ones in these attacks. A developer may unknowingly check in a service account token or kubeconfig file to a public git repository that could leave a cluster vulnerable.

The most important protective measure is preventing the creation of malicious workloads from Daemonsets. There’s also a case for observability tooling, as many crypto jacking operations are discovered through unexpected traffic spikes.

Since this attack used an image to create the malicious pods, setting up an admission control policy that prevents the creation of workloads coming from untrusted image sources would work. However, you’d either have to enforce the policy broadly or employ a real-time KSPM detection solution to understand exactly where you’re having issues, then use the admission controller surgically as you fix the configurations in code.

RBAC-Buster plan of attack

The attacker attempts to gain a foothold in a Kubernetes environment by scanning for a misconfigured API server that would allow unauthenticated requests from users with privileges. Attackers used privileged access to list secrets and discover the kube-system namespace.

They created a new ClusterRole with admin privileges and a new Service Account in the namespace, binding the two together to give the ClusterRole’s admin privileges to the Service Account. The attacker looked for AWS keys to gain access to the cloud service provider. They then used a Daemonset to deploy malicious pods for crypto mining across the cluster, using a container image. 

The initial step in this attack assumes that not only is your Kubernetes API server open, but it’s also accepting requests that privileged users have. The rest of the attack operates with this privileged access. 

What you can do to protect from RBAC-Buster

To spread laterally, the attackers used the same Daemonset technique as in the Dero campaign — a reminder to prevent creation of malicious workloads from Daemonsets. Check your API server configurations and audit your RBAC permissions to protect against this attack.

Preventing future attacks

The team that discovered RBAC-Buster said 60% of exposed clusters found had an active campaign running. This doesn’t mean 60% of all clusters are exposed. But attackers are searching for mistakes, misconfigurations and a way into your Kubernetes environment.

Most clusters were only accessible for a few hours, highlighting the ephemeral nature of Kubernetes clusters and how what today points to an exploitation and exposure might tomorrow be closed off to attackers. This means a nightmare in remediation if you’re working with polling intervals that can’t show these changes over time.

Relying solely on admission control or reverse-engineering detection on runtime events when the next attack comes either won’t detect it at all or will detect it too late. You need a real-time, combined view of Kubernetes risk. Defense-in-depth is best practice. But, if defense-in-depth provides no view of how all the different components work together, you’re still one step behind the attacker. 

Jimmy Mesta is CTO and co-founder of KSOC.

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers

Credit: Source link

ShareTweetSendSharePin

Related Posts

Why It’s Time to Abandon the ‘Set It and Forget It’ Model – Unite.AI
AI & Technology

Why It’s Time to Abandon the ‘Set It and Forget It’ Model – Unite.AI

September 9, 2026
Lyft Is Now Offering Waymo Rides In Nashville
AI & Technology

Lyft Is Now Offering Waymo Rides In Nashville

September 9, 2026
Harvey Secures 0M in Fresh Funding, Valuation Climbs to .5B – Unite.AI
AI & Technology

Harvey Secures $550M in Fresh Funding, Valuation Climbs to $15.5B – Unite.AI

September 9, 2026
How To Take Full Advantage Of Gemini When Planning Your Next Trip
AI & Technology

How To Take Full Advantage Of Gemini When Planning Your Next Trip

September 9, 2026
Next Post
Inside Sphere: Is the new Vegas attraction the future of entertainment?

Inside Sphere: Is the new Vegas attraction the future of entertainment?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Arizona firefighter donates kidney to her firefighter husband

Arizona firefighter donates kidney to her firefighter husband

September 4, 2026
A rare look inside the Pope’s summer residence garden

A rare look inside the Pope’s summer residence garden

September 3, 2026
Audit Your Subscriptions Every Few Months

Audit Your Subscriptions Every Few Months

September 3, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!