<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>siloscape - Latest News &amp; Reviews</title>
	<atom:link href="https://www.thetechoutlook.com/tag/siloscape/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.thetechoutlook.com/tag/siloscape/</link>
	<description>Daily Tech News, Interviews, Reviews and Updates</description>
	<lastBuildDate>Tue, 08 Jun 2021 11:01:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://www.thetechoutlook.com/wp-content/uploads/2019/09/cropped-favicon-1-150x150.png</url>
	<title>siloscape - Latest News &amp; Reviews</title>
	<link>https://www.thetechoutlook.com/tag/siloscape/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Siloscape, a new malware for cryptojacking in town that is targeting windows servers now</title>
		<link>https://www.thetechoutlook.com/news/security/siloscape-a-new-malware-for-cryptojacking-in-town-that-is-targeting-windows-servers-now/</link>
					<comments>https://www.thetechoutlook.com/news/security/siloscape-a-new-malware-for-cryptojacking-in-town-that-is-targeting-windows-servers-now/#respond</comments>
		
		<dc:creator><![CDATA[Team Tech Outlook]]></dc:creator>
		<pubDate>Tue, 08 Jun 2021 11:01:52 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[siloscape]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=16484</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Wolfrat android malware facebook" decoding="async" fetchpriority="high" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-696x392.jpg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-1068x601.jpg 1068w" sizes="(max-width: 1200px) 100vw, 1200px" /></div>
<p>“This malware can leverage the computing resources in a Kubernetes cluster for cryptojacking and potentially exfiltrate sensitive data from hundreds of applications running in the compromised clusters,” Prizmant said. Typically, an attack starts with the malware operators abusing a known vulnerability to gain remote code execution inside a Windows container, which is then used to [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/siloscape-a-new-malware-for-cryptojacking-in-town-that-is-targeting-windows-servers-now/">Siloscape, a new malware for cryptojacking in town that is targeting windows servers now</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Wolfrat android malware facebook" decoding="async" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-696x392.jpg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/05/WolfRat-Android-Malware-attacking-Facebook-WhatsApp-messenger-users-1068x601.jpg 1068w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>“This malware can leverage the computing resources in a Kubernetes cluster for cryptojacking and potentially exfiltrate sensitive data from hundreds of applications running in the compromised clusters,” Prizmant said.</p>
<p>Typically, an attack starts with the malware operators abusing a known vulnerability to gain remote code execution inside a Windows container, which is then used to run Siloscape. Next, the malware escapes the container to compromise the host, checks if the host has privileges to create new Kubernetes deployments, and connects to the C&amp;C server using Tor.</p>
<p>To escape the container, the malware impersonates <em>CExecSvc.exe</em> and then creates a symbolic link to its local containerized X drive to the host&#8217;s C drive. Next, it searches for specific Kubernetes files and makes sure it can execute kubectl commands.</p>
<p>The main focus of the malware is to remain undetected on the compromised environment. Unlike other container-targeting malware that were designed for resource hijacking and denial of service (DoS), it opens a backdoor into the cluster, which allows its operators to perform all kinds of malicious activities.</p>
<p>Given that Siloscape targets Windows Server containers, administrators should make sure their cloud environments are properly secured and configured. Thus, Hyper-V containers should be employed for operations that rely on containerization as a security boundary, and Kubernetes clusters should be securely configured.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/siloscape-a-new-malware-for-cryptojacking-in-town-that-is-targeting-windows-servers-now/">Siloscape, a new malware for cryptojacking in town that is targeting windows servers now</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/siloscape-a-new-malware-for-cryptojacking-in-town-that-is-targeting-windows-servers-now/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
