Malicious Image

T1204.003

Sub-technique of T1204 User Execution.View on attack.mitre.org

About this technique

Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Backdoored images may be uploaded to a public repository via Upload Malware, and users may then download and deploy an instance or container from the image without realizing the image is malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that executes cryptocurrency mining, in the instance or container.

Adversaries may also name images a certain way to increase the chance of users mistakenly deploying an instance or container from the image (ex: Match Legitimate Resource Name or Location).

Detection rules12

Rules on DetectionCode tagged with T1204.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk12

RuleTypeRiskData source
ASL AWS ECR Container Upload Outside Business HoursAnomalyNULLASL AWS CloudTrail
ASL AWS ECR Container Upload Unknown UserAnomalyNULLASL AWS CloudTrail
AWS ECR Container Scanning Findings HighTTPNULLAWS CloudTrail DescribeImageScanFindings
AWS ECR Container Scanning Findings Low Informational UnknownAnomalyNULLAWS CloudTrail DescribeImageScanFindings
AWS ECR Container Scanning Findings MediumAnomalyNULLAWS CloudTrail DescribeImageScanFindings
AWS ECR Container Upload Outside Business HoursAnomalyNULLAWS CloudTrail PutImage
AWS ECR Container Upload Unknown UserAnomalyNULLAWS CloudTrail PutImage
Cisco Isovalent - Non Allowlisted Image UseAnomalyNULLCisco Isovalent Process Exec
Cisco Isovalent - Pods Running Offensive ToolsAnomalyNULLCisco Isovalent Process Exec
Correlation by Repository and RiskCorrelationNULL
Correlation by User and RiskCorrelationNULL
Risk Rule for Dev Sec Ops by RepositoryCorrelationNULL

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupTeamTNT

TeamTNT has relied on users to download and execute malicious Docker images.

References2

  1. Aqua Security Cloud Native Threat Report June 2021 Open source
    Team Nautilus. (2021, June). Attacks in the Wild on the Container Supply Chain and Infrastructure. Retrieved August 26, 2021.
  2. Summit Route Malicious AMIs Open source
    Piper, S.. (2018, September 24). Investigating Malicious AMIs. Retrieved March 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.