timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.11k stars 90 forks source link

[Intel]: https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads #723

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Malware reports

Parent threat

Defense Evasion, Command and Control, Impact

Finding

https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads

Industry reference

uses:Python attack:T1496:Resource Hijacking attack:T1620:Reflective Code Loading attack:T1102:Web Service attack:T1190:Exploit Public-Facing Application attack:T1105:Ingress Tool Transfer attack:T1140:Deobfuscate/Decode Files or Information attack:T1027.002:Software Packing uses:Non-persistentStorage

Malware reference

PyLoose XMRig

Actor reference

No response

Component

Linux

Scenario

No response