HomeSecurityKinsing malware compromises Kubernetes clusters

Kinsing malware compromises Kubernetes clusters

The Kinsing malware is now attacking Kubernetes clusters, exploiting existing vulnerabilities in container images and poorly secured, exposed PostgreSQL containers.

Microsoft's Defender for Cloud team has recognized that the same tactics are being used more frequently lately, indicating that malicious actors are actively targeting specific entry points.

Kinsing is a Linux malware with a history of targeting containerized environments for cryptocurrency mining, using the compromised server's hardware resources to generate revenue for the threat actors.

Kinsing hackers are known for using dangerous vulnerabilities like Log4Shell and recently an Atlassian Confluence RCE to infiltrate their victims' systems and remain there.

See also: Air France and KLM report account breaches

Kinsing malware compromises Kubernetes clusters

Scan for container image defects

Microsoft has observed an increase in two tactics used by Kinsing operators to gain initial access to a Linux server – exploiting a vulnerability present in container images or misconfigured PostgreSQL database servers.

When searching for vulnerabilities to exploit, attackers target remote code execution vulnerabilities in images that allow them to deploy malicious payloads.

See also: Darknet drug markets: They have moved to custom Android apps for increased privacy

According to Microsoft Defender for Cloud data, threat actors are attempting to exploit vulnerabilities in the following applications as an initial entry point into targeted systems:

  • PHPUnit
  • Liferay
  • Oracle WebLogic
  • WordPress

In the WebLogic cases, hackers are scanning for CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883, all remote code executionthat affect Oracle's product.

To minimize this problem, you should only use the latest versions of images from official sources or trusted websites.

Microsoft also recommends minimizing access to exposed containers by using IP whitelists and following the principles of least privilege.

Kinsing Kubernetes

PostgreSQL attack

Microsoft's security team has discovered an increase in malicious actors exploiting improperly configured PostgreSQL servers.

By using the incorrect “trust authentication” setting, attackers can easily gain access to PostgreSQL databases, as it instructs them that “any person who is able to connect to the server is authorized to enter its database.”

Another common mistake is assigning too large a range of IP addresses, which can provide hackers with a gateway to access the server. This careless mistake can prove extremely damaging if not addressed properly and quickly.

Even if IP access configuration is strict, Microsoft says Kubernetes is still susceptible to ARP (Address Resolution Protocol) poisoning, so attackers could spoof applications in the cluster to gain access.

To ensure that PostgreSQL is properly configured for optimal security, be sure to follow the project's security guidelines outlined on its website and implement the recommended measures.

See also: OnlyFans: Fake dating sites are misleading users

Finally, Microsoft says Defender for Cloud can detect permissible settings and misconfigurations in PostgreSQL containers and help administrators mitigate risks before hackers exploit them.

For PostgreSQL administrators whose servers were infected with Kinsing, BigBinary's Sreeram Venkitesh wrote an article about how the malware infected their device and how they eventually removed it.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS