Spinning YARN - A New Linux Malware Campaign Targets Docker, Apache Hadoop, Redis and Confluence
released on 2024-03-08 @ 05:00:55 PM
A new Linux malware campaign has been discovered that targets misconfigured servers running Docker Engine API, Apache Hadoop YARN, Confluence, and Redis. The attackers use four novel Golang binaries to identify vulnerable hosts and conduct RCE attacks, initially gaining access via Docker before deploying XMRig miners, reverse shells, and user mode rootkits on compromised systems.