Technique.View on attack.mitre.org
Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.
In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as docker exec to execute a command within a running container. In Kubernetes, if an adversary has sufficient permissions, they may gain remote execution in a container in the cluster via interaction with the Kubernetes API server, the kubelet, or by running a command such as kubectl exec.
Rules on DetectionCode tagged with T1609.
| Rule | Level | Log source |
|---|---|---|
| Kubernetes Potential Enumeration Activity | medium | kubernetes / NULL |
| Potential Remote Command Execution In Pod Container | medium | kubernetes / application |
| Potential Sidecar Injection Into Running Deployment | medium | kubernetes / application |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupTeamTNT | TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers. |
| Used by | Procedure example |
|---|---|
| MalwareCanisterWorm | CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl. |
| MalwareHildegard | Hildegard was executed through the kubelet API run command and by executing commands on running containers. |
| MalwareKinsing | Kinsing was executed with an Ubuntu container entry point that runs shell scripts. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`. |
| ToolPeirates | Peirates can use `kubectl` or the Kubernetes API to run commands. |
| MalwareSiloscape | Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.