IOC Radar
TLP:WHITE6 IOCs

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

SE
Securelist
Published May 29, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREunknownCAPABILITYMiraiVICTIMunknown
Adversary
Infrastructure
Capability(1)
Victim

Attack Flow9 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/9
Exploit Public-Facing Application
ActionExploit vulnerable applications
Attackers exploit vulnerabilities in public-facing applications, such as web applications running in containers, to gain initial access.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise6

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2025-32463
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2026-24061
exploitintel-blogmalware
High
62
Jun 2, 26
CVECVE-2025-49844
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2023-4911
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2025-55182
exploitintel-blogmalware
High
73
Jun 2, 26
CVECVE-2021-4034
exploitintel-blogmalware
Medium
51
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph6 total IOCs
CVE
CVE6Malware1REPORTWhat’s in the container? AMirai
scroll to zoom · drag to pan · click IOC to open