The cloud infrastructure has become an arena of struggle not only between defenders and attackers, but also between the malicious groups themselves: the new CAI worm infects servers, steals accounts, mines cryptocurrency and removes competitors’ programs.
Cloud AI Infrastructure Attack Framework, or CAI, is a centralized network of infected devices. The malware attacks Internet-based tools Docker, Kubernetes, Redis, etc., Kubelet and Ray that companies use to run applications and manage cloud systems.
Hunt.io specialists for the first time discovered the CAI-related infrastructure on June 15. Over the next three weeks, the operator moved from testing to full-fledged attacks and infection of networks. The source code found signs of help from language models, and individual techniques resembled the methods of cloud worms PCPJack and TeamPCP.
The CAI scans the Internet in search of vulnerable services, places the found targets in an automatic queue and coordinates attacks through a single control server. After entering the computer, a program for mining cryptocurrency, a secrets and a hidden remote access channel in Python are downloaded.
Individual modules are searched for and complete the TeamPP and PCPJack processes, as well as delete files associated with competitors. Thus, the operator releases the resources of the infected system and tries to maintain sole control over the stolen data and computing power.
The logs of control servers showed active attempts to operate, and operations with cryptocurrency wallets confirmed several successful infections. The CAI is not yet a complex device, but is developing rapidly and has already turned from a test project into a working platform for attacks on cloud infrastructure.
Cloud AI Infrastructure Attack Framework, or CAI, is a centralized network of infected devices. The malware attacks Internet-based tools Docker, Kubernetes, Redis, etc., Kubelet and Ray that companies use to run applications and manage cloud systems.
Hunt.io specialists for the first time discovered the CAI-related infrastructure on June 15. Over the next three weeks, the operator moved from testing to full-fledged attacks and infection of networks. The source code found signs of help from language models, and individual techniques resembled the methods of cloud worms PCPJack and TeamPCP.
The CAI scans the Internet in search of vulnerable services, places the found targets in an automatic queue and coordinates attacks through a single control server. After entering the computer, a program for mining cryptocurrency, a secrets and a hidden remote access channel in Python are downloaded.
Individual modules are searched for and complete the TeamPP and PCPJack processes, as well as delete files associated with competitors. Thus, the operator releases the resources of the infected system and tries to maintain sole control over the stolen data and computing power.
The logs of control servers showed active attempts to operate, and operations with cryptocurrency wallets confirmed several successful infections. The CAI is not yet a complex device, but is developing rapidly and has already turned from a test project into a working platform for attacks on cloud infrastructure.