unit42 · Crawled Sep 10, 2026

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

1 IoCs
Read original article ↗

AI Summary

This research demonstrates a post-exploitation technique enabling an attacker with root access on a compromised Kubernetes node to spoof workload identities in SPIFFE/SPIRE environments by manipulating Linux cgroup metadata. The attacker can trick the SPIRE agent into issuing legitimate SPIFFE Verifiable Identity Documents (SVIDs) belonging to co-located workloads, enabling identity impersonation and lateral movement. The trust model of SPIFFE/SPIRE collapses when node integrity is breached, as workload attestation relies on unspoofed cgroup information. The researchers developed an open-source tool called Spooffe to automate this attack for defensive testing purposes.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo Spooffe Details →