Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Misconfigured Docker instances are being hacked to mine cryptocurrency
    Cryptocurrency

    Misconfigured Docker instances are being hacked to mine cryptocurrency

    May 28, 20252 Mins Read



    • Security researchers spot new campaign targeting Docker instances
    • The attack deploys a cloud crypto miner, and a worm for further propagation
    • The miner generates the Dero currency

    Hackers are building a botnet out of misconfigured Docker API instances and using it to mine the Dero cryptocurrency, experts have warned.

    Security researchers from Kaspersky reported finding a “container zombie outbreak” that started with an exposed Docker API.

    “This led to the running containers being compromised and new ones being created not only to hijack the victim’s resources for cryptocurrency mining but also to launch external attacks to propagate to other networks,” they explained.


    You may like

    Negotiations ongoing?

    In this zombie outbreak, the “patient zero” is a misconfigured API that’s left open to the internet. There, the attackers deploy a piece of malware disguised as ‘nginx’, a high-performance, open-source web server and reverse proxy server.

    The malware scans for vulnerable instances and infects them, and then creates new malicious containers and forces existing ones to mine Dero. At the same time, it continues to spread to other systems.

    This is a two-step process, Kaspersky explains. Nginx is the propagation tool that scans for new victims, with the miner being a cloud-based solution. Both components are written in Golang, which makes them rather difficult to detect.

    Kaspersky also says that unlike traditional cryptojacking campaigns, this one doesn’t rely on a command & control (C2) server, but instead spreads autonomously, like a worm.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Docker should check their API settings, and make sure it’s not exposed to the internet. Furthermore, they should fortify their login credentials, and perform regular security audits and monitoring.

    While cybercriminals usually hijack servers to mine Monero with the XMRig, this is not the first time researchers spotted Dero. According to The Hacker News, CrowdStrike saw Kubernetes clusters being targeted back in March 2023, and a subsequent iteration of the same campaign was spotted by Wiz in June 2024.

    Similar to Monero, Dero is also a privacy-focused Layer 1 blockchain, built to support decentralized applications (dApps) and smart contracts.

    Via The Hacker News

    You might also like



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    MEDIROM launches cryptocurrency strategy with next-generation proof of human technology, World

    Cryptocurrency

    Ethereum Shatters Records, Surges 250% From April Lows, Why Is Cryptocurrency Rising? | Cryptocurrency News

    Cryptocurrency

    How the digital euro could change the way people pay

    Cryptocurrency

    AshToken: Empowering Nigerian businesses with cryptocurrency solutions

    Cryptocurrency

    Top Blockchain Applications and Use Cases

    Cryptocurrency

    After US stablecoin laws: EU wants to hurry up with the digital euro

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Agriculture reinsurance: Axis Re’s technical edge in a complex market

    Precious Metal

    Gold slips below $3,300 amid US court ruling and Fed outlook

    Cryptocurrency

    A Guide for Beginners and Newcomers – Forbes Advisor

    Editors Picks

    Durham agricultural college helps young people get into farming

    August 6, 2025

    Crypto payment services firm says more than 92,000 affected by data breach

    October 21, 2024

    Unicoin Signs Agreement to Acquire Controlling Stake in DiamondLake, Expanding into Digital Asset Treasury Business | Taiwan News

    June 24, 2025

    5 questions pour comprendre la Copper Mark, certification obtenue par plusieurs mines de cuivre en RDC

    April 12, 2025
    What's Hot

    Closing prices for crude oil, gold and other commodities

    July 12, 2024

    Xinjiang’s agriculture develops well via advanced technologies: Turkish journalists

    August 13, 2024

    ASAP Utilities remporte le prix du « Meilleur complément Microsoft Excel » au Global Excel Summit 2025

    February 7, 2025
    Our Picks

    Alternative investments: Gardening offers more than just savings – Mary Holm

    June 20, 2025

    78 years of currency evolution: From the paper rupee’s Independence to digital currency

    August 15, 2024

    le Irish Gold Rush – Masculin.com

    March 4, 2025
    Weekly Top

    How to get the Gold Beanstalk in Grow a Garden

    August 23, 2025

    Metal Gear Solid Delta Should Have Followed Silent Hill 2’s Lead

    August 23, 2025

    Project to construct 1,000 ponds lunched in Thoothukudi to boost groundwater, agricultural production

    August 23, 2025
    Editor's Pick

    Agriculture & Food Science Exploration Day a success – Austin Daily Herald

    July 19, 2024

    Once a crypto critic, Donald Trump amasses Ethereum worth millions

    August 16, 2024

    Hanoi Police Crack Down on Multi-Billion Dollar Crypto Scam

    July 12, 2024
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.