{"id":54677,"date":"2023-11-22T16:15:25","date_gmt":"2023-11-22T16:15:25","guid":{"rendered":"https:\/\/www.darkreading.com\/black-hat\/rootkit-turns-kubernetes-from-orchestration-to-subversion"},"modified":"2023-11-22T16:15:25","modified_gmt":"2023-11-22T16:15:25","slug":"rootkit-turns-kubernetes-from-orchestration-to-subversion","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/","title":{"rendered":"Rootkit Turns Kubernetes From Orchestration to Subversion"},"content":{"rendered":"<p>As software development focuses on continuous integration and deployment, orchestration platforms like Kubernetes have taken off, but that popularity has put them in attackers&#8217; crosshairs.<\/p>\n<p>Most successful attacks \u2014 at least those publicly reported \u2014 have led to the deployment of cryptomining-focused containers, basically stealing cloud compute resources from businesses to power cryptocurrency mining. Yet the attacks could be much worse \u2014 infecting Kubernetes clusters with rootkits would result in collections of containers controlled by attackers, says Nicholas Lang, a security researcher with cloud-infrastructure security firm Sysdig, who will present a prototype rootkit at Black Hat Europe next month.<\/p>\n<p>The successful compromise of a Kubernetes cluster by a rootkit could allow an attacker to hide malicious containers on the system, for example. The rootkit can hide other containerized payloads and take more sophisticated actions escaping notice in the system, because they are hidden from the operating system, he says.<\/p>\n<p>&#8220;Even though it interacts with the kernel to get these containers up and in place, after that &#8230; the rootkit is able to hide these containerized payloads,&#8221; Lang says. &#8220;The rootkit is part of the initial payload &#8230; and then, you know, future stages will do more sophisticated things in secret because they&#8217;re hidden from the operating system by the rootkit.&#8221;<\/p>\n<p>Kubernetes is a popular way of automating the configuration, deployment, and management \u2014 that is, &#8220;orchestration&#8221; \u2014 of containers, virtualized software environments that can run a wide variety of workloads, from servers to applications to software-defined networks. As such, the technology is critical for cloud applications in today&#8217;s fast-moving world of software development and deployment.<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" data-image=\"nzb9xeq3dxb9\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" data-sys-asset-uid=\"blt151ca5dcdc0a6f7a\" alt=\"Pie chart from Kubernetes security survey\">\n<\/picture><figcaption>Vulnerabilities and misconfigurations are top concerns for Kubernetes. Source: Red Hat<\/figcaption><\/figure>\n<p>For the same reason, however, attackers have targeted the infrastructure. In February, an attacker <a href=\"https:\/\/www.darkreading.com\/risk\/pernicious-permissions-kubernetes-cryptomining-cloud-data-heist\" target=\"_blank\" rel=\"noopener\">compromised a misconfigured Kubernetes cluster<\/a>, first installing cryptojacking containers and then stealing intellectual property and sensitive data. A month earlier, Microsoft researchers discovered that the <a href=\"https:\/\/www.darkreading.com\/cloud\/microsoft-kinsing-malware-kubernetes-containers-postgresql\" target=\"_blank\" rel=\"noopener\">Kinsing malware<\/a> had started targeting poorly configured database containers on Kubernetes platforms.<\/p>\n<h2 class=\"regular-text\">Kubernetes Under Attack<\/h2>\n<p>The spate of attacks have software firms worried. Two-thirds of companies (67%) have delayed or slowed down an application deployment due to a security concern with Kubernetes, according to Red Hat&#8217;s &#8220;<a href=\"https:\/\/www.redhat.com\/en\/resources\/kubernetes-adoption-security-market-trends-overview\" target=\"_blank\" rel=\"noopener\">2023 State of Kubernetes Security Report<\/a>.&#8221;<\/p>\n<p>While attackers have exploited vulnerabilities in Kubernetes infrastructure, misconfigured applications running in containers are, by far, the most common way that the orchestration platform is compromised, says Sysdig&#8217;s Lang.<\/p>\n<p>&#8220;A misconfigured Web server or Web application gives the attacker shell access to that virtual machine or inside that container,&#8221; he says. &#8220;Depending on the attacker&#8217;s sophistication level, they&#8217;ll either realize that they&#8217;re inside of a container or a virtual machine, or whatever, and try to escape to the host, or they realize that they&#8217;re in a Kubernetes environment by doing a little bit of poking and prodding.&#8221;<\/p>\n<p>While a specific Linux kernel rootkit, <a href=\"https:\/\/blog.aquasec.com\/advanced-persistent-threat-techniques-container-attacks\" target=\"_blank\" rel=\"noopener\">known as Diamorphine<\/a>, has occasionally been used to compromise Kubernetes clusters, Kubernetes-focused rootkits have not yet become popular.<\/p>\n<p>Lang argues that will change, and as a view into the future, he and another security researcher, Andrew Hughes of Narf Industries, plan to demonstrate their own Kubernetes rootkit at the <a href=\"https:\/\/www.blackhat.com\/eu-23\/briefings\/schedule\/index.html#orchestrate-this-kubernetes-rootkit-34489\" target=\"_blank\" rel=\"noopener\">Black Hat Europe Conference in December<\/a>. &#8220;The real change is the attackers learning that Kubernetes is increasingly common in the cloud, and how to deal with it and how to get around it, and how to make use of it even,&#8221; he says.<\/p>\n<h2 class=\"regular-text\">Kubernetes Admins Need Visibility<\/h2>\n<p>Typically, a victim would have to see a rootkit getting loaded or a vulnerability being exploited by the attacker to catch an attack on a Kubernetes cluster, Lang says. However, admins can also look out for kernel modules that get loaded during runtime, which really should not happen in a production setting, he says.<\/p>\n<p>&#8220;These systems don&#8217;t really do a whole lot of crazy stuff, so if you see [kernel modules loading] inside a container or on host that runs containers, you can be pretty confident something bad is going on,&#8221; he says. &#8220;Otherwise, catching it is very, very difficult, because a lot of it happens in user space or in an application layer where you don&#8217;t have a lot of deep insight.&#8221;<\/p>\n<p>Admins should also ask their red team to conduct a group exercise, working against defenders to attack, and then with defenders to analyze the attack \u2014 a process referred to as purple teaming.<\/p>\n<p>Sysdig runs its own honeypot, exposing Kubernetes ports to potential attacks, and typically, the first probes come quickly, Lang says.<\/p>\n<p>&#8220;Within minutes, sometimes seconds, it&#8217;s already getting attacked,&#8221; he says. &#8220;So purple teaming is how you will find and close your gaps, and then not putting Kubernetes on the Internet in the first place is a great way to not get attacked.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/black-hat\/rootkit-turns-kubernetes-from-orchestration-to-subversion\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kubernetes compromises have usually led to attackers creating cryptomining containers, but the outcomes could be much worse, say researchers presenting at the Black Hat Europe conference.Read More <a href=\"https:\/\/www.darkreading.com\/black-hat\/rootkit-turns-kubernetes-from-orchestration-to-subversion\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-54677","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-22T16:15:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Rootkit Turns Kubernetes From Orchestration to Subversion\",\"datePublished\":\"2023-11-22T16:15:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/\"},\"wordCount\":795,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt151ca5dcdc0a6f7a\\\/654c0293507a4804078446a2\\\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/\",\"name\":\"Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt151ca5dcdc0a6f7a\\\/654c0293507a4804078446a2\\\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"datePublished\":\"2023-11-22T16:15:25+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt151ca5dcdc0a6f7a\\\/654c0293507a4804078446a2\\\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt151ca5dcdc0a6f7a\\\/654c0293507a4804078446a2\\\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/rootkit-turns-kubernetes-from-orchestration-to-subversion\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Rootkit Turns Kubernetes From Orchestration to Subversion\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/","og_locale":"en_US","og_type":"article","og_title":"Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-11-22T16:15:25+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Rootkit Turns Kubernetes From Orchestration to Subversion","datePublished":"2023-11-22T16:15:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/"},"wordCount":795,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/","url":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/","name":"Rootkit Turns Kubernetes From Orchestration to Subversion 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","datePublished":"2023-11-22T16:15:25+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt151ca5dcdc0a6f7a\/654c0293507a4804078446a2\/redhat-kubernetes-threats-pie-chart.jpg?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/rootkit-turns-kubernetes-from-orchestration-to-subversion\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Rootkit Turns Kubernetes From Orchestration to Subversion"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=54677"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54677\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=54677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=54677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=54677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}