Siloscape is Windows malware associated with attacks on containerized environments, particularly Windows containers in Kubernetes deployments. It is designed to run after an attacker has already obtained access to a vulnerable Windows container, then exploit a container escape weakness to break out to the underlying host. Following escape, it performs host-level actions including thread impersonation to assume the security context of a privileged service thread, aiding post-compromise execution on the host.
The malware conducts environment discovery tailored to container orchestration by searching for the kubectl binary, indicating awareness of Kubernetes administration tooling and likely interest in broader cluster access or follow-on operations. Siloscape also uses native Windows API functionality during execution and includes simple obfuscation or decryption logic, including byte-wise XOR-based decryption of protected configuration data such as command-and-control credentials.
For command and control, Siloscape has been observed using both Tor-based communications and IRC, reflecting an effort to conceal operator infrastructure while maintaining interactive control channels. Its tradecraft aligns with post-exploitation activity in cloud-native and containerized Windows environments, with emphasis on privilege escalation through container escape, host compromise, and operational anonymity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263 to escalate privileges. ... APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. ... multiple groups/tools exploit various CVEs to escalate privileges.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
AsyncRAT can proxy C2 through a Tor client. Attor has used Tor for C2 communication. Cyclops Blink has used Tor nodes for C2 traffic. GreyEnergy has used Tor relays for Command and Control servers. Siloscape uses Tor to communicate with C2. WannaCry uses Tor for command and control traffic.
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enterprise New Software: ... Siloscape
Malware that decrypts its C2 password with byte-by-byte XOR and writes embedded Tor archive data to disk.
Malware that uses various native API calls during operation.
Malware that communicates with command-and-control infrastructure over Tor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.