{
  "Event": {
    "analysis": "1",
    "date": "2026-06-11",
    "extends_uuid": "",
    "info": "[Threat Intel] How to defend ARM64 cloud infrastructure",
    "protected": false,
    "publish_timestamp": "1782230729",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1782230729",
    "uuid": "b91d23b7-24fc-4cac-87d6-d5dc6b6bfd67",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#fb3bcd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Gather Victim Host Information - T1592\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#d0c0c7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Escape to Host - T1611\"",
        "relationship_type": ""
      },
      {
        "colour": "#4cb5c3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deploy Container - T1610\"",
        "relationship_type": ""
      },
      {
        "colour": "#9dfeaa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Abuse Elevation Control Mechanism - T1548\"",
        "relationship_type": ""
      },
      {
        "colour": "#20f80d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Command and Scripting Interpreter - T1059\"",
        "relationship_type": ""
      },
      {
        "colour": "#c7d6f8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Container Administration Command - T1609\"",
        "relationship_type": ""
      },
      {
        "colour": "#3780c6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"",
        "relationship_type": ""
      },
      {
        "colour": "#6d779a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"vulnerability\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#170057",
        "local": false,
        "name": "rectifyq:sub-category=\"critical-vuln\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b0068",
        "local": false,
        "name": "rectifyq:topic=\"cloud\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578840",
        "to_ids": false,
        "type": "link",
        "uuid": "f40e44fe-f9c5-432b-9250-8260be0cf937",
        "value": "https://www.reversinglabs.com/blog/defend-cloud-infrastructure-itscape",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578840",
        "to_ids": false,
        "type": "text",
        "uuid": "926cd3dc-0f74-444e-b201-2ad337a45e61",
        "value": "ITScape (CVE-2026-46316) is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM/arm64, disclosed by researcher Hyunwoo Kim. The flaw stems from a race condition in the vgic_its_invalidate_cache() function causing a double-put use-after-free, enabling host kernel code execution. Since the bug exists in in-kernel KVM rather than QEMU user-space, successful exploitation grants host kernel privileges, posing significant risk to multi-tenant ARM64 cloud environments. The vulnerability can be chained with local privilege escalation when guest root access is unavailable. Affected kernels range from commit 8201d1028caa through 13031fb6b835, when the patch was applied. Two YARA rules have been developed for detection: one targeting hardcoded constants from the proof-of-concept, another identifying behavioral patterns in privilege drop sequences."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578840",
        "to_ids": false,
        "type": "text",
        "uuid": "bab19ba7-3521-403b-9778-8aefe7b7e0a8",
        "value": "Name: How to defend ARM64 cloud infrastructure\nAuthor: AlienVault\nAdversary: \nTags: [\"itscape\", \"yara rules\", \"arm64\", \"cloud infrastructure\", \"cve-2026-46316\", \"kvm\", \"guest-to-host escape\", \"vgic-its\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1592\", \"T1082\", \"T1005\", \"T1611\", \"T1610\", \"T1548\", \"T1059\", \"T1609\", \"T1204\", \"T1068\"]\nIndustries: []"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578840",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "ee3bdf39-04f4-408f-b486-0a20ae36e2d7",
        "value": "CVE-2026-46316"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:22/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782101774",
        "to_ids": true,
        "type": "sha1",
        "uuid": "8a04ec67-bb79-465c-8c82-0dd9dbcb8df4",
        "value": "838ea8d6b201e2eed181f3fd890f99ecb6178b52",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:22/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782101774",
        "to_ids": true,
        "type": "sha1",
        "uuid": "30ecd26b-fe23-4ea9-946c-2feabe60c399",
        "value": "fbf0b6abd651622864eb921f891b3e7c538fc8a9",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1782097042",
        "uuid": "312d0f69-609b-43ba-a959-1801d69a0d09",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1782097042",
            "to_ids": false,
            "type": "text",
            "uuid": "35404f79-c451-4da4-81b9-f5c9b1e71456",
            "value": "ITScape_ExploitConstants_1"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1782097042",
            "to_ids": false,
            "type": "comment",
            "uuid": "6b22e5d3-3e8c-41cd-b6c4-2d3bab82d62e",
            "value": "Detects constants used in ITScape exploit PoC"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1782097042",
            "to_ids": true,
            "type": "yara",
            "uuid": "31908425-bebf-42ff-bd28-1a3591073a23",
            "value": "rule ITScape_ExploitConstants_1\r\n{\r\n    meta:\r\n        author = \"Malware Utkonos\"\r\n        date = \"2026-05-11\"\r\n        description = \"Detects constants used in ITScape exploit PoC.\"\r\n        reference = \"https://github.com/V4bel/ITScape/blob/main/poc.c\"\r\n        poc = \"e0ab84da2d2783c8cae3624e8ce58b99ad79219753b249671ff7f743abdacc35\"\r\n    strings:\r\n        $orderly_poweroff   = { 2cf90d800080ffff }\r\n        $poweroff_cmd       = { c803d0820080ffff }\r\n        $neigh_gc_work_func = { 502d1d830080ffff }\r\n        $pmu_fn_linked      = { b80e09800080ffff }\r\n        $gadget_rt          = { dcc6d7800080ffff }\r\n\r\n        // canary magic (\"LEAKLEAD\" = 0x4c45414b4c454144 byte-swapped)\r\n        $leak_sentinel      = { 4441454c4b41454c }\r\n\r\n        // payload: \"/bin/touch /ITScape\" packed as three u64s\r\n        $sc_write_bin_tou   = { 2f62696e2f746f75 }  // /bin/tou\r\n        $sc_write_ch_ITSc   = { 6368202f49545363 }  // ch /ITSc\r\n        $sc_write_ape       = { 6170650000000000 }  // ape\\0\r\n    condition:\r\n        5 of them\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1782097061",
        "uuid": "ed9aef04-8cee-4672-8adb-8e693695beef",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1782097061",
            "to_ids": false,
            "type": "text",
            "uuid": "026a0237-1771-4769-a33f-a8d697cb0746",
            "value": "ITScape_KVM_PrivDrop_1"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1782097061",
            "to_ids": false,
            "type": "comment",
            "uuid": "b36afd49-6701-4bae-bb12-66b4b34e8160",
            "value": "Detects /dev/kvm group rw check and drop to setgroups/setgid/setuid(1000) used in ITScape PoC."
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1782097061",
            "to_ids": true,
            "type": "yara",
            "uuid": "a60b22df-ffaa-4456-bc24-0c7bfc906b2a",
            "value": "rule ITScape_KVM_PrivDrop_1\r\n{\r\n    meta:\r\n        author = \"Malware Utkonos\"\r\n        date = \"2026-05-11\"\r\n        description = \"Detects /dev/kvm group rw check and drop to setgroups/setgid/setuid(1000) used in ITScape PoC.\"\r\n        reference = \"https://github.com/V4bel/ITScape/blob/main/poc.c\"\r\n        poc = \"e0ab84da2d2783c8cae3624e8ce58b99ad79219753b249671ff7f743abdacc35\"\r\n    strings:\r\n        $kvm = \"/dev/kvm\"\r\n\r\n        $op = { e0??4?b9 00041f12 1f180071 ?1[2]54 010080d2 000080d2 [3]9? 007d8052 [3]9? ?0[2]35 007d8052 [3]9? ?0[2]35 }\r\n            // 004025cc  e0c340b9   ldr     w0, [sp, #0xc0 {guest_memfd.reserved[0].d}]  // load stat st_mode; offset floats\r\n            // 004025d0  00041f12   and     w0, w0, #0x6                                 // mask S_IRGRP|S_IWGRP (0x4|0x2)\r\n            // 004025d4  1f180071   cmp     w0, #0x6                                     // both group rw bits must be set\r\n            // 004025d8  c1f0ff54   b.ne    0x4023f0\r\n            // 004025dc  010080d2   mov     x1, #0                                       // setgroups(0, NULL)\r\n            // 004025e0  000080d2   mov     x0, #0\r\n            // 004025e4  b3feff97   bl      setgroups\r\n            // 004025e8  007d8052   mov     w0, #0x3e8                                   // setgid(1000)\r\n            // 004025ec  71feff97   bl      setgid\r\n            // 004025f0  00f0ff35   cbnz    w0, 0x4023f0\r\n            // 004025f4  007d8052   mov     w0, #0x3e8                                   // setuid(1000)\r\n            // 004025f8  a6fdff97   bl      setuid\r\n            // 004025fc  a0efff35   cbnz    w0, 0x4023f0\r\n\r\n    condition:\r\n        $kvm and $op\r\n}"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782102607",
        "uuid": "0a3098cb-6310-4fad-8a0a-cdcaadfcf3ac",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "PoC",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782102607",
            "to_ids": true,
            "type": "md5",
            "uuid": "3a52f7dd-6ba3-4c5c-892d-90d49ec10e78",
            "value": "5f5e67d5ed28d671f79871a103345a85",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "PoC",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782101773",
            "to_ids": true,
            "type": "sha1",
            "uuid": "20779e07-6267-4ef5-bb29-2186db5da7aa",
            "value": "8d8c384c502c3042cee2e015ef13a707f3a12f5c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "PoC",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782101773",
            "to_ids": true,
            "type": "sha256",
            "uuid": "c34b5e17-0991-4e51-b4f8-1caddb9a2624",
            "value": "e0ab84da2d2783c8cae3624e8ce58b99ad79219753b249671ff7f743abdacc35",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#260093",
                "local": false,
                "name": "rectifyq:ioc=\"no-detection-by-any-vendor\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782099828",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "4a127f8f-d240-4c16-9746-a73272b2ca1d",
            "value": "12288:xSnvf7wO1Ocd689zaV25vV6gPv9yr1ltqztB6760kLlcKFGtUAn2t+fDTU:xSj1Ot8TZ60ayGtUAn7DT"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782099828",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "b629a1a5-3a91-4188-80f7-e1fa8e79fd71",
            "value": "769008"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782099828",
            "to_ids": true,
            "type": "vhash",
            "uuid": "62ba9433-4481-46ac-a94d-26aae1184e38",
            "value": "8024cb2a522f650972255bb1e71418e0"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1782099828",
            "to_ids": true,
            "type": "filename",
            "uuid": "5120573d-85cd-4f17-892d-aee6787f23c0",
            "value": "puvzl.exe"
          },
          {
            "category": "Other",
            "comment": "Checked: 22/06/2026\nLast-scan\t:  20/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782099828",
            "to_ids": false,
            "type": "text",
            "uuid": "8c732312-63a2-4906-9ff3-10bc7ccfd6f7",
            "value": "PoC\r\nType Description: ELF\nMicrosoft: None\nVT Total Detection:0/62\nFirst Submission:2026-06-11T13:11:25.000000+00:00\nLast Submission:2026-06-11T13:11:25.000000+00:00"
          }
        ]
      }
    ]
  }
}