Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Misconfigured Docker instances are being hacked to mine cryptocurrency
    Cryptocurrency

    Misconfigured Docker instances are being hacked to mine cryptocurrency

    May 28, 20252 Mins Read



    • Security researchers spot new campaign targeting Docker instances
    • The attack deploys a cloud crypto miner, and a worm for further propagation
    • The miner generates the Dero currency

    Hackers are building a botnet out of misconfigured Docker API instances and using it to mine the Dero cryptocurrency, experts have warned.

    Security researchers from Kaspersky reported finding a “container zombie outbreak” that started with an exposed Docker API.

    “This led to the running containers being compromised and new ones being created not only to hijack the victim’s resources for cryptocurrency mining but also to launch external attacks to propagate to other networks,” they explained.


    You may like

    Negotiations ongoing?

    In this zombie outbreak, the “patient zero” is a misconfigured API that’s left open to the internet. There, the attackers deploy a piece of malware disguised as ‘nginx’, a high-performance, open-source web server and reverse proxy server.

    The malware scans for vulnerable instances and infects them, and then creates new malicious containers and forces existing ones to mine Dero. At the same time, it continues to spread to other systems.

    This is a two-step process, Kaspersky explains. Nginx is the propagation tool that scans for new victims, with the miner being a cloud-based solution. Both components are written in Golang, which makes them rather difficult to detect.

    Kaspersky also says that unlike traditional cryptojacking campaigns, this one doesn’t rely on a command & control (C2) server, but instead spreads autonomously, like a worm.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Docker should check their API settings, and make sure it’s not exposed to the internet. Furthermore, they should fortify their login credentials, and perform regular security audits and monitoring.

    While cybercriminals usually hijack servers to mine Monero with the XMRig, this is not the first time researchers spotted Dero. According to The Hacker News, CrowdStrike saw Kubernetes clusters being targeted back in March 2023, and a subsequent iteration of the same campaign was spotted by Wiz in June 2024.

    Similar to Monero, Dero is also a privacy-focused Layer 1 blockchain, built to support decentralized applications (dApps) and smart contracts.

    Via The Hacker News

    You might also like



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Barclays Invests in Ubyx to Build Digital Money Infrastructure for Tokenised Deposits and Stablecoins

    Cryptocurrency

    Bitcoin Explained: Digital Gold & The Future of Money

    Cryptocurrency

    Barclays Invests in Ubyx to Advance Digital Money Connectivity

    Cryptocurrency

    The digital euro that Europe urgently needs

    Cryptocurrency

    Sterling Heights joins other cities in regulating cryptocurrency machines

    Cryptocurrency

    Bitlero – Leading Platform for Global Cryptocurrency Traders in 2026

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Metal Gear Solid Delta, Super Robot Wars Y Keep PS5 Software in the Japanese Top 10

    Cryptocurrency

    Bitcoin as a Global Reserve Asset? Mark Cuban & Senator Lummis Discuss BTC’s Potential

    Stock Market

    A Home Renovation Trend Might Be Spell Trouble For These Dividend Stocks

    Editors Picks

    Britain and China ‘will battle for Bitcoin queen’s fortune’: £5billion of cryptocurrency could plug hole in Rachel Reeves’ budget

    September 30, 2025

    Mining Bitcoin with 5 Best Free Crypto Cloud Mining Sites in 2025

    February 11, 2025

    Building energy resilience in an uncertain world

    December 11, 2025

    Will Weakness in Faraday Technology Corporation’s (TWSE:3035) Stock Prove Temporary Given Strong Fundamentals?

    August 19, 2024
    What's Hot

    FinTech IPO Flat as Industry Processes New CFPB Rule 1033

    October 25, 2024

    Adam Silver, l’homme chargé de faire briller la NBA dans le monde

    January 24, 2025

    Avec Nickel, on peut créer un compte en Espagne, sans besoin du NIE

    April 6, 2025
    Our Picks

    Top retirement insights for consumers to know in 2024

    October 30, 2024

    Which investments can I hold in a stocks and shares ISA?

    April 25, 2025

    6 mannequins stars célèbrent la puissance féminine dans les pages du Vogue France de mai 2025

    April 28, 2025
    Weekly Top

    What happens to your retirement accounts in bankruptcy?

    January 7, 2026

    Netherlands Commercial Real Estate 2026 in The Netherlands

    January 7, 2026

    Zilch buys Lithuanian lender Fjord Bank to secure European banking licence

    January 7, 2026
    Editor's Pick

    PNM warns about copper theft trends

    September 8, 2025

    Arab Real Estate Investment : bénéfice de 5,8 millions de livres égyptiennes pour l’exercice

    April 29, 2025

    India’s agricultural production surges to record high in 2024-25

    March 10, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.