Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Misconfigured Docker instances are being hacked to mine cryptocurrency
    Cryptocurrency

    Misconfigured Docker instances are being hacked to mine cryptocurrency

    May 28, 20252 Mins Read



    • Security researchers spot new campaign targeting Docker instances
    • The attack deploys a cloud crypto miner, and a worm for further propagation
    • The miner generates the Dero currency

    Hackers are building a botnet out of misconfigured Docker API instances and using it to mine the Dero cryptocurrency, experts have warned.

    Security researchers from Kaspersky reported finding a “container zombie outbreak” that started with an exposed Docker API.

    “This led to the running containers being compromised and new ones being created not only to hijack the victim’s resources for cryptocurrency mining but also to launch external attacks to propagate to other networks,” they explained.


    You may like

    Negotiations ongoing?

    In this zombie outbreak, the “patient zero” is a misconfigured API that’s left open to the internet. There, the attackers deploy a piece of malware disguised as ‘nginx’, a high-performance, open-source web server and reverse proxy server.

    The malware scans for vulnerable instances and infects them, and then creates new malicious containers and forces existing ones to mine Dero. At the same time, it continues to spread to other systems.

    This is a two-step process, Kaspersky explains. Nginx is the propagation tool that scans for new victims, with the miner being a cloud-based solution. Both components are written in Golang, which makes them rather difficult to detect.

    Kaspersky also says that unlike traditional cryptojacking campaigns, this one doesn’t rely on a command & control (C2) server, but instead spreads autonomously, like a worm.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Docker should check their API settings, and make sure it’s not exposed to the internet. Furthermore, they should fortify their login credentials, and perform regular security audits and monitoring.

    While cybercriminals usually hijack servers to mine Monero with the XMRig, this is not the first time researchers spotted Dero. According to The Hacker News, CrowdStrike saw Kubernetes clusters being targeted back in March 2023, and a subsequent iteration of the same campaign was spotted by Wiz in June 2024.

    Similar to Monero, Dero is also a privacy-focused Layer 1 blockchain, built to support decentralized applications (dApps) and smart contracts.

    Via The Hacker News

    You might also like



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Will Ethereum Ever Overtake the Dollar in Digital Finance?

    Cryptocurrency

    Kyrgyzstan’s Bank Approves Escrow Accounts for Transactions

    Cryptocurrency

    SEC, Cambridge University & Busha launch landmark digital Assets Programme in Nigeria 

    Cryptocurrency

    Super Money SA Launches South Africa’s First Bank-Backed Rand Stablecoin – IT News Africa

    Cryptocurrency

    Africa Stablecoin Summit 2025 Showcases the Future of Digital Money in Africa Powered by Binance | Supported by Tether, VISA, and Telcoin

    Cryptocurrency

    Bitcoin vs Traditional Currency: Explained

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Investments

    Mark Ballas Revealed The Sweet Reason Why He Came Out Of Dancing With The Stars Retirement To Compete On Season 34

    Commodities

    Le Métal Pless acquiert un gardien de but

    Fintech

    How the BVNK-Circle Partnership Will Expand USDC Utility

    Editors Picks

    Prothèses d’épaules imprimées en 3D : un processus plus durable

    April 16, 2025

    SuisseGold Adopts XRP As Payment Method. Here’s the Significance – Times Tabloid

    August 18, 2024

    Top Wall Street analysts like these 3 dividend stocks for enhanced returns – CNBC

    June 29, 2025

    Dow futures turn positive; Glencore sees lower profits

    April 30, 2025
    What's Hot

    Fintech CEO targets Africa payment fr…

    October 22, 2025

    Australian Shares Slip As Banks And Tech Offset Gains In Commodities

    August 27, 2024

    Construction sector ramping up tech investments to address labour gap: KPMG survey

    June 18, 2025
    Our Picks

    Investments need to work smarter as we work harder – HSBC Life

    August 5, 2025

    1 Magnificent TSX Monthly Dividend Stock Down 6% I’m Accumulating Now

    May 23, 2025

    EMIRA PROPERTY FUND LIMITED – Unaudited summarised interim financial results for the six months ended 30 September 2025 and dividend declaration – Sens

    November 12, 2025
    Weekly Top

    Will Ethereum Ever Overtake the Dollar in Digital Finance?

    November 14, 2025

    Trade deals to boost US ag industry with new market access to Latin America

    November 14, 2025

    SECP Updates NBFC Regulations to Encourage Fintech Innovation

    November 14, 2025
    Editor's Pick

    Fidelity: Gold Passing Baton à Bitcoin

    May 17, 2025

    INSIGHT: Why huge flaws with U.S. AML rules means ‘trillions’ of fintech transactions are not properly tracked

    October 28, 2024

    Limassol’s Booming Real Estate Market Attracts More Property

    October 25, 2024
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.