Peirates is a Go-based open-source post-exploitation framework designed to help red teams and defenders understand how a compromised container can be used to explore a Kubernetes cluster, escalate privileges, and pivot into cloud services. Reported capabilities include using stolen Kubernetes service account tokens to perform operations and initiating port scans against specified IP addresses. The content also states that Peirates models Kubernetes privilege-escalation and cloud-pivot techniques, and that it has been misused previously by SCARLETEEL and TeamTNT. Its activity is associated with Kubernetes and cloud environments, particularly scenarios involving compromised containers, cluster reconnaissance, privilege escalation, and abuse of connected cloud identities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Peirates is a Go-based open-source framework, originally created to help red teams and defenders understand how a compromised container can be leveraged to explore a cluster, escalate privileges and pivot into cloud services.
Peirates is a Go-based open-source framework, originally created to help red teams and defenders understand how a compromised container can be leveraged to explore a cluster, escalate privileges and pivot into cloud services.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Annotations ID Technique Tactic T1204.003 Malicious Image Execution Default Configuration
Peirates can use stolen service account tokens to perform its operations.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Kubernetes post-exploitation framework used to enumerate service accounts, inspect secrets, switch namespaces, query cloud metadata endpoints, steal credentials, and pivot from compromised containers into clusters and cloud services.
A cloud attack tool that operates using stolen service account tokens.
Cloud/container-focused offensive tool that can initiate port scans against specified IP addresses.
Malware capable of initiating port scans against specified IP addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.