Commando

Threat Actor updated 3 months ago (2024-06-06T09:17:35.251Z)
Download STIX
Preview STIX
Commando is a threat actor identified as being behind the "Commando Cat" attack campaign, which poses significant cybersecurity risks through the abuse of exposed Docker remote API servers. The Commando Cat attack sequence involves deploying benign containers generated using the publicly-available Commando project, an open-source GitHub project that creates Docker images on-demand for developers. This cryptojacking campaign leverages Docker as an initial access vector and abuses the service to mount the host's filesystem before running a series of interdependent payloads directly on the host. There's an uncertainty regarding the origin or identity of the threat actor behind Commando Cat, but there are overlaps in scripts and IP addresses with other groups like Team TNT, suggesting potential connections or copycat actions. The Commando threat actor has been involved in numerous malicious activities, with evidence linking it to Latin-American crime syndicates such as Commando Vermelho, Primeiro Comando da Capital (PCC), and Cartel Jalisco New Generation (CJNG) in financial fraud. Furthermore, a 2020 Congressional Research Service report indicates that the GRU, Russia’s military intelligence agency, operates both as an intelligence agency and as a military organization responsible for battlefield reconnaissance and the operation of Russia’s Spetsnaz military commando units. These associations suggest that Commando's activities could have broad geopolitical implications. In unrelated news, John Carpenter is working on a horror action game called Toxic Commando, developed in collaboration with Saber Interactive and Focus Entertainment. The game was revealed at the Summer Game Fest and will be released for PC, PS5, and Xbox Series X in 2024. The game, where players cooperatively fight hordes of zombies with guns and a wide variety of vehicles, shares a name with the threat actor but has no known connection to the cybersecurity issues described above.
Description last updated: 2024-06-06T09:16:54.587Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Commando Cat
2
Commando Cat is a threat actor, or malicious entity, that has been identified as the force behind an attack campaign exploiting exposed Docker remote API servers. This campaign is notable due to its unique initial step, which involves deploying harmless containers using the open-source GitHub projec
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Exploit
Docker
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Commando Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
3 months ago
'Commando Cat' Digs Its Claws into Exposed Docker Containers
Trend Micro
3 months ago
Commando Cat: A Novel Cryptojacking Attack Abusing Docker Remote API Servers
CERT-EU
6 months ago
INTERPOL Financial Fraud Assessment: A Global Threat Boosted By Technology
Krebs on Security
7 months ago
From Cybercrime Saul Goodman to the Russian GRU
DARKReading
7 months ago
'Commando Cat' Is Second Campaign of the Year Targeting Docker
CERT-EU
9 months ago
DOD Hosts Singapore Defense Minister for Security Discussions
CERT-EU
10 months ago
Hacker Threat: Israeli Police Advise Citizens not to Answer Unknown Calls
CERT-EU
a year ago
Man in jet suit flies over backwater leaving spectators spellbound
CERT-EU
10 months ago
Indian Hack-for-Hire Group Targeted U.S., China, and More for Over 10 Years
CERT-EU
a year ago
How a dysfunctional mission in the Caribbean became 'the pivotal point' for the creation of US Special Operations Command
MITRE
2 years ago
Handy guide to a new Fivehands ransomware variant
CERT-EU
a year ago
British commandos have trained hundreds of Ukrainian marines in the 'art' of amphibious raids
CERT-EU
a year ago
Everything announced at Summer Game Fest kickoff 2023 | Digital Trends
CERT-EU
2 years ago
Feb 8: Buonasera Mag