Threat Intelligence2021
Advanced Persistent Threat Techniques in Container Attacks
By Assaf Morag
Analysis of how advanced persistent threat (APT) groups are adapting their techniques to target containerized environments and cloud-native infrastructure. APT groups have traditionally focused on traditional IT infrastructure, but are now evolving to exploit cloud-native technologies.
This research examines how APT groups are leveraging container technologies, Kubernetes, and cloud services in their attack campaigns, representing a significant evolution in threat actor capabilities.
APT Techniques in Containers
- Container escape and privilege escalation
- Kubernetes cluster compromise
- Supply chain attacks through container images
- Long-term persistence in cloud environments