SCARLETEEL

Kubernetes as a Pivot into the Cloud Control Plane

THREAT ACTOR
SCARLETEEL
INFRASTRUCTURE
AWS, Kubernetes, Fargate
ASSESSMENT
High significance for workload-to-cloud attack paths

Executive Summary

SCARLETEEL is a highly sophisticated threat actor associated with attacks against cloud environments in which compromised compute workloads were used to obtain credentials, escalate privileges, and seamlessly move deeper into AWS infrastructure.

In a documented 2023 operation, SCARLETEEL compromised JupyterLab notebook containers deployed in a Kubernetes environment. The attackers extracted AWS credentials and subsequently exploited an AWS policy misconfiguration to escalate to AdministratorAccess. They then created new IAM users and access keys, ultimately deploying cryptocurrency miners on EC2 infrastructure.

The Cloud Control Plane Threat

The attack perfectly demonstrates a critical cloud-native security problem: A compromised workload can become an identity bridge directly into the cloud control plane. The attacker did not need to begin with direct AWS administrative access—the workload itself provided the required foothold.

Initial Environment

The relevant architecture involved distributed cloud workloads that were implicitly trusted by the broader cloud environment.

THE FOOTHOLD ARCHITECTURE
AWS INFRASTRUCTURE
↓
↓
Kubernetes
Fargate
↓
JupyterLab Containers
↓
COMPROMISED WORKLOAD

Observed Attack Sequence

The documented SCARLETEEL operation executed a methodical progression from a simple container compromise all the way up to full environment administrative control. They also utilized Kubernetes-focused offensive tooling, including Peirates, and attempted to exploit cloud metadata infrastructure to harvest additional credentials.

THE ATTACK CHAIN
Compromise JupyterLab
↓
Container Access
↓
Credential Collection
↓
AWS Reconnaissance
↓
Privilege Escalation
↓
AdministratorAccess
New IAM Users
Access Keys
↓
EC2 Deployment
↓
CRYPTOMINING

Credential Theft

A particularly important element of this campaign was the attacker's strict focus on credential harvesting rather than merely exploiting the workload for compute.

The compromised environment became exponentially more useful because it natively exposed:

This fundamentally alters the blast radius equation:

Container Compromise
↓
IDENTITY COMPROMISE

Privilege Escalation

SCARLETEEL exploited a customer policy mistake that permitted escalation to full AdministratorAccess. This demonstrates a critical property of cloud-native attack chains:

The vulnerability does not necessarily need to exist inside Kubernetes. The attacker can simply use Kubernetes as the starting point for discovering a weakness residing deep in the cloud control plane.

Analyst Assessment

The attack can therefore be perfectly modeled as a cascading series of trust assumptions:

WORKLOAD TRUST
↓
CLOUD IDENTITY
↓
IAM PERMISSIONS
↓
CONTROL PLANE
↓
CLOUD RESOURCES

Each transition represents an opportunity for security controls to fail. The workload may be legitimate. The identity may be legitimate. The AWS API calls may be syntactically legitimate. The maliciousness emerges strictly from the sequence and the context.

Opsonance Point of View

SCARLETEEL is particularly relevant to Opsonance because it illustrates exactly why runtime defense cannot be separated from identity security.

OPSONANCE RUNTIME PERSPECTIVE
WORKLOAD
├── PROCESS
├── FILE
├── NETWORK
├── TOKEN
└── CREDENTIAL
↓
CLOUD API

A container accessing a cloud metadata endpoint, retrieving credentials, and subsequently making unusual external connections represents a distinct behavioral chain.

The objective is not merely to identify a compromised Kubernetes object. It is to identify the runtime transition from workload execution to infrastructure control.

Key Finding

CONCLUSION

SCARLETEEL conclusively demonstrates that Kubernetes compromise and cloud compromise cannot be treated as independent security domains. A workload can become the absolute bridge between the two.

References