Summary:
Researchers found SCARLETEEL, a sophisticated cloud operation that stole proprietary data, operating in a customer environment. To access cloud services and collect sensitive data, the Scareteel attack targets public-facing web apps running in containers. It all started with the exploitation of a vulnerable pod. According to researchers, the threat actors' true goal—the theft of proprietary software—was disguised as the cryptojacking attempt.[/subscribe_to_unlock_form]
Summary:
Researchers found SCARLETEEL, a sophisticated cloud operation that stole proprietary data, operating in a customer environment. To access cloud services and collect sensitive data, the Scareteel attack targets public-facing web apps running in containers. It all started with the exploitation of a vulnerable pod. According to researchers, the threat actors' true goal—the theft of proprietary software—was disguised as the cryptojacking attempt.[emaillocker id="1283"]
First, the attacker can obtain access to the Kubernetes cluster that is being self-managed and is being hosted inside of an AWS cloud account. Then it starts a cryptominer to earn profits or serve as a distraction, and it gets access to credentials through a worker's temporary credentials for the Instance Metadata Service (IMDS) v1 to list AWS resources and gather data. After the attackers get access to the container, they download an XMRig coinminer, which is thought to work as a decoy, as well as a script to steal the Kubernetes pod's login information. The attacker moved laterally by using the credentials. Attackers might also be able to access Lambda data such functions, configurations, and access keys depending on how the AWS cluster role is configured.
At that point, S3 bucket enumeration also takes place, and files kept in cloud buckets are probably going to include vital information for attackers, like login credentials. The attacker was able to retrieve and view more than 1 TB of data during this specific attack, including customer scripts, troubleshooting tools, and logs files, according to researchers. The stolen credentials were then used to make Amazon API requests to create backdoor users and groups in the company's cloud environment, steal further credentials, or gain persistence. The cloud environment was then used to spread these accounts further.

Over the previous year, there has been a 56% increase in cyberattacks in the cloud. The most frequent goals are getting cloud persistence, stealing private information, and building additional resources like Elastic Compute Cloud (EC2) instances for cryptomining. To get access to an Amazon account and steal proprietary software and credentials, the attacker first compromised a containerized workload. They also tried to expand their reach throughout the entire corporation by using a Terraform state file to connect to other connected AWS accounts.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/03/hackers-exploit-containerized.html
[/emaillocker]