New fileless malware attacks “PyLoose” target cloud workloads
Researchers at cybersecurity firm Wiz Inc. today detailed a newly discovered Python-based fileless malware targeting cloud workloads.
See also: HCA confirms breach after 11 million patient data stolen

Dubbed “PyLoose,” the attack is said to be the first publicly documented Python-based fileless attack targeting cloud workloads. A fileless attack does not rely on traditional executable files to carry out an attack, but instead exploits tools and features built into the target system’s software. Fileless attacks pose a significant challenge to conventional security solutions due to their tactical avoidance.
See also: Phishing and scam pages increased significantly in 2022
The PyLoose attack exploits the Linux fileless technique, memfd, to load an XMRig Miner directly into memory, thus bypassing the need to write payloads to disk, taking advantage of the capabilities of the operating system.
PyLoose was first detected on June 22nd and launched with initial access via a publicly accessible Jupyter Notebook service. The malware creators then downloaded a fileless payload from a Pastebin-like website into the Python runtime's memory, bypassing the need for disk storage and streamlining the attack process by simplifying the command structure.
See also: Organizations lack visibility into malware attacks

Researchers were unable to link the attack to a specific threat group – however, they note that the use of an open data exchange service to host the Python payload, the adaptation of fileless execution in Python, and the integration of the XMRig mining engine configuration suggest that this is a highly specialized and experienced threat actor.
While PyLoose may be the first documented fileless attack based on Python, there are steps that can be taken to protect against it. The researchers recommend that users avoid exposing public services like Jupyter Notebook, which could allow code execution. Robust authentication methods, such as using multi-factor authentication and a centrally managed identity platform , can also provide further protection.
Information source: siliconangle.com
