Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Misconfigured Docker instances are being hacked to mine cryptocurrency
    Cryptocurrency

    Misconfigured Docker instances are being hacked to mine cryptocurrency

    May 28, 20252 Mins Read



    • Security researchers spot new campaign targeting Docker instances
    • The attack deploys a cloud crypto miner, and a worm for further propagation
    • The miner generates the Dero currency

    Hackers are building a botnet out of misconfigured Docker API instances and using it to mine the Dero cryptocurrency, experts have warned.

    Security researchers from Kaspersky reported finding a “container zombie outbreak” that started with an exposed Docker API.

    “This led to the running containers being compromised and new ones being created not only to hijack the victim’s resources for cryptocurrency mining but also to launch external attacks to propagate to other networks,” they explained.


    You may like

    Negotiations ongoing?

    In this zombie outbreak, the “patient zero” is a misconfigured API that’s left open to the internet. There, the attackers deploy a piece of malware disguised as ‘nginx’, a high-performance, open-source web server and reverse proxy server.

    The malware scans for vulnerable instances and infects them, and then creates new malicious containers and forces existing ones to mine Dero. At the same time, it continues to spread to other systems.

    This is a two-step process, Kaspersky explains. Nginx is the propagation tool that scans for new victims, with the miner being a cloud-based solution. Both components are written in Golang, which makes them rather difficult to detect.

    Kaspersky also says that unlike traditional cryptojacking campaigns, this one doesn’t rely on a command & control (C2) server, but instead spreads autonomously, like a worm.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Docker should check their API settings, and make sure it’s not exposed to the internet. Furthermore, they should fortify their login credentials, and perform regular security audits and monitoring.

    While cybercriminals usually hijack servers to mine Monero with the XMRig, this is not the first time researchers spotted Dero. According to The Hacker News, CrowdStrike saw Kubernetes clusters being targeted back in March 2023, and a subsequent iteration of the same campaign was spotted by Wiz in June 2024.

    Similar to Monero, Dero is also a privacy-focused Layer 1 blockchain, built to support decentralized applications (dApps) and smart contracts.

    Via The Hacker News

    You might also like



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    As crypto industry expands, U.S. slashes office examining dirty money safeguards of cryptocurrency exchanges

    Cryptocurrency

    Cryptocurrency Fuels Human Trafficking, Child Abuse, and Online Scams, Report Finds

    Cryptocurrency

    Police arrest three for cryptocurrency fraud

    Cryptocurrency

    Court acquits defendants in cryptocurrency mining case

    Cryptocurrency

    Top 5 Cloud Mining Platforms for Cryptocurrency in 2026 – Why HashBitcoin Stands Out

    Cryptocurrency

    Better Cryptocurrency to Buy Now and Hold for 10 Years: XRP vs. Bitcoin

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Il faut que les entreprises du métal prennent le virage du réemploi

    Fintech

    la fintech anglaise myPOS rachète Toporder pour se renforcer en France

    Cryptocurrency

    UK’s last local currency axed due to rise of digital and card payments

    Editors Picks

    How a Florida man, 21, went from ‘citizen hero’ to ‘hacker’ who stole $13M in cryptocurrency

    October 1, 2025

    Airbus Identifies New Problem With Metal Panels On Some A320s

    December 1, 2025

    1 Top Cryptocurrency to Buy Before It Soars 180%, According to Tom Lee of Fundstrat

    December 6, 2025

    D.C. United’s Steven Birnbaum retires after painful injuries and recoveries

    July 16, 2024
    What's Hot

    Boisbreteau : Le projet agrivoltaïque d’Oriolles déborde sur Boisbreteau

    March 10, 2025

    Manufacturing, agricultural exports up strongly as coal shipments slump – Economy

    March 17, 2025

    IIFL Finance bonds base issue of Rs 500 cr fully subscribed

    February 17, 2026
    Our Picks

    Martin Lewis-approved ‘buy to save energy’ gadget coming to Lidl next week

    October 10, 2025

    Property investor grows Team Valley footprint

    December 18, 2025

    MARA Gains on Bitcoin Revenue Milestone

    September 9, 2025
    Weekly Top

    Household energy bills in Great Britain forecast to fall by £117 a year | Energy bills

    February 18, 2026

    Stock Market Highlights Feb 18: Sensex, Nifty extend winning streak to 3rd day; Financials and metals lead, IT lags

    February 18, 2026

    Finance Ministry places government bonds for UAH 12.7 billion and EUR 92 million

    February 18, 2026
    Editor's Pick

    Fintech giant Pine Labs might get listed in mid-November

    October 13, 2025

    SEBI mulls allowing FPIs, banks in commodity derivatives trade

    September 17, 2025

    Best inflation-busting property investments in each state

    July 23, 2024
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.