216.73.216.36

Stopping Sobolan Malware with Aqua Runtime Protection

· Published 12/03/2025 11:48 · Modified 12/03/2025 11:55

Export JSON

Essential information

Published
12/03/2025 11:48
Modified
12/03/2025 11:55
Tags
2025-03-12 cloud-native cryptomining evasion jupyter notebooks persistence runtime protection sobolan
Related entities
9 observables, 12 techniques (mitre), 1 malware

Description

A new attack campaign targeting interactive computing environments like has been discovered. The attack involves downloading a compressed file from a remote server, which, when executed, deploys multiple malicious tools to exploit the server and establish . The campaign poses a significant risk to environments by enabling unauthorized access and long-term control over compromised systems. The attack flow includes initial access through an unauthenticated JupyterLab instance, downloading and extracting malicious files, executing scripts to launch additional binaries, and establishing while evading detection. The malware deploys cryptominers and attempts to kill competing processes. solutions can effectively detect, block, and mitigate these threats using real-time threat intelligence, malware scanning, and customizable policies.

External references