Siloscape malware threatens cloud environments by targeting Windows containers

Surface Laptop 4 Amd 2021 Keyboard Lights
Surface Laptop 4 Amd 2021 Keyboard Lights (Image credit: Daniel Rubino / Windows Central)

What you need to know

  • A malware that targets Windows containers was discovered in March 2021.
  • The man who found it, Daniel Prizmant, dubbed it "Siloscape."
  • Siloscape aims to steal data and inject cryptocurrency miners.

Unit 42's Daniel Prizmant says he's discovered "the first known malware targeting Windows containers." Unit 42 is the cybersecurity consulting group for Palo Alto Networks that has announced its discovery of Siloscape and disclosed the dangers the malware has for cloud environments as we know them. Though the group has seen malware that goes after containers in Linux "due to the popularity of that operating system in cloud environments," it gives Siloscape the distinction of being the first to go after Windows containers.

"Siloscape is heavily obfuscated malware targeting Kubernetes clusters through Windows containers," Prizmant said in his highly technical blog post outlining Siloscape and the threat it poses. "Its main purpose is to open a backdoor into poorly configured Kubernetes clusters in order to run malicious containers."

Compromising entire clusters means that Siloscape can allow its hacker to cause a lot more trouble than had they just gotten access to a single container by itself. With access to a cluster, a hacker can get a hold of a lot more info, be it usernames, login credentials, or entire databases. Whatever's hosted in the cluster and the apps it's running, Siloscape may exfiltrate.

Siloscape

Source: Palo Alto Networks / Unit 42 (Image credit: Source: Palo Alto Networks / Unit 42)

Exfiltration of stolen data isn't the only activity Siloscape is built for. It can also inject cryptojackers to divert computational resources toward crypto mining activities.

"We identified 23 active Siloscape victims and discovered that the server was being used to host 313 users in total, implying that Siloscape was a small part of a broader campaign," Prizmant stated in his post. "I also discovered that this campaign has been taking place for more than a year."

The post recommends that users take Microsoft's advice on not using Windows containers for security purposes, recommending Hyper-V containers instead. If you want the full scoop on Siloscape, check out the blog post linked above. The key takeaway here is to know that the era of mainstream cloud hacking is upon us.

CATEGORIES
Robert Carnevale

Robert Carnevale is the News Editor for Windows Central. He's a big fan of Kinect (it lives on in his heart), Sonic the Hedgehog, and the legendary intersection of those two titans, Sonic Free Riders. He is the author of Cold War 2395. Have a useful tip? Send it to robert.carnevale@futurenet.com.

Read more
Apple Store in Bangkok, Thailand
Microsoft flags macOS bug — remotely bypassing Apple's sophisticated System Integrity Protection (SIP) security solution and allowing unauthorized third-party rootkit installs
Binary code displayed on a laptop screen and Guy Fawkes mask are seen in this illustration photo.
Microsoft blocks critical Secure Boot loophole after over 7 months — fortifying Windows 11 against sophisticated firmware attacks camouflaged as verified UEFI apps
Cisco Systems headquarters in San Jose, California, US
Cisco debuts AI defense to combat misuse of AI tools, data leakage, and sophisticated threats — despite Sam Altman's confidence in AI's ability to prevent existential doom even with a 99.999999% probability
Microsoft Majorana 1 chip designed for quantum computing
Microsoft dismisses quantum computing skepticism: "There is a century-old scientific process established by the American Physical Society for resolving disputes"
A DeepSeek artificial intelligence logo and icons on various smartphones or laptops.
DeepSeek is reportedly sending intricate user data to Chinese telecom despite US ban — weeks after suffering a "large-scale cyberattack"
Microsoft Edge Scareware blocker
How to enable Edge's Scareware blocker and protect yourself from online scams
Latest in Microsoft
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports — Microsoft responds (Updated)
Steve Ballmer and Bill Gates, former CEOs of Microsoft.
Bill Gates says Satya Nadella almost missed the cut for CEO of Microsoft — Even with Steve Ballmer's support
HP Reverb G2 VR headset
Was Windows Mixed Reality as bad as I remember? I look back at the failed VR platform that was ahead of its time.
Microsoft Majorana 1 chip designed for quantum computing
Microsoft dismisses quantum computing skepticism: "There is a century-old scientific process established by the American Physical Society for resolving disputes"
The Microsoft logo on a smartphone and laptop arranged in Crockett, California, US, on Friday, Dec. 29, 2023.
"Would you say there is a reasonable balance between what you contribute to Microsoft and what you get in return?" Two-thirds of Microsoft employees say YES — as AI engineers get preferential compensation packages.
Like a Dragon Pirate Yakuza in Hawaii screenshot
Microsoft blocks (some) Windows 11 pirates while Lenovo steals the show at Mobile World Congress
Latest in News
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports — Microsoft responds (Updated)
Photo of Microsoft's new sign-in page for Xbox.com using the Microsoft Edge browser.
Over one billion users will get a new Microsoft user experience, and it has a dark mode
The Thing: Remastered key art
The Thing comes to Xbox Cloud Gaming's "Stream Your Own Game" library alongside other new arrivals
Promotional screenshot of heroes fighting a giant in Pillars of Eternity
Obsidian's classic Baldur's Gate successor 'Pillars of Eternity' is getting a surprise turn-based mode later this year, alongside other updates
Atomfall
Atomfall reviews and Metacritic scores are in: Here's a roundup of what everyone's saying about this new Game Pass survival game
Screenshot of one of the new flat world presets in Minecraft.
Minecraft testing new flat world presets and a better way to locate your friends in-game