Siloscape

S0623

Malware.View on attack.mitre.org

About this malware

Siloscape is malware that targets Kubernetes clusters through Windows containers. Siloscape was first observed in March 2021.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1027
Obfuscated Files or Information

Siloscape itself is obfuscated and uses obfuscated API calls.

T1059.003
Windows Command Shell

Siloscape can run cmd through an IRC channel.

T1068
Exploitation for Privilege Escalation

Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host.

T1069
Permission Groups Discovery

Siloscape checks for Kubernetes node permissions.

T1071
Application Layer Protocol

Siloscape connects to an IRC server for C2.

T1083
File and Directory Discovery

Siloscape searches for the Kubernetes config file and other related files using a regular expression.

T1090.003
Multi-hop Proxy

Siloscape uses Tor to communicate with C2.

T1106
Native API

Siloscape makes various native API calls.

T1134.001
Token Impersonation/Theft

Siloscape impersonates the main thread of CExecSvc.exe by calling NtImpersonateThread.

T1140
Deobfuscate/Decode Files or Information

Siloscape has decrypted the password of the C2 server with a simple byte by byte XOR. Siloscape also writes both an archive of Tor and the unzip binary to disk from data embedded within the payload using Visual Studio’s Resource Manager.

T1190
Exploit Public-Facing Application

Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability.

T1518
Software Discovery

Siloscape searches for the kubectl binary.

T1609
Container Administration Command

Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster.

T1611
Escape to Host

Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of NtSetInformationSymbolicLink.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit 42 Siloscape Jun 2021 Open source
    Prizmant, D. (2021, June 7). Siloscape: First Known Malware Targeting Windows Containers to Compromise Cloud Environments. Retrieved June 9, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.