Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
ID: 3e1eca76-5441-5ba1-ba29-bfbc402ecdd6
STIX ID: report--3e1eca76-5441-5ba1-ba29-bfbc402ecdd6
Feed Name: The Register (Security)
Trend Micro researchers observed attackers exploiting unprotected Docker Remote API servers to deploy the perfctl cryptominer: adversaries create privileged containers from an ubuntu:mantic-20240405 image with pid:host, use nsenter to escape to the host, run a Base64-encoded installer that enforces single-instance checks, downloads a disguised binary (PHP extension), kills competing processes, and establishes persistence and a backdoor. Honeypots trapped attempts and prior reporting suggests widespread targeting; recommended mitigations include restricting and authenticating Docker Remote API access, avoiding privileged containers, patching, and following container security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
