logo

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

ID: 3e1eca76-5441-5ba1-ba29-bfbc402ecdd6

STIX ID: report--3e1eca76-5441-5ba1-ba29-bfbc402ecdd6

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-10-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Trend Micro researchers observed attackers exploiting unprotected Docker Remote API servers to deploy the perfctl cryptominer: adversaries create privileged containers from an ubuntu:mantic-20240405 image with pid:host, use nsenter to escape to the host, run a Base64-encoded installer that enforces single-instance checks, downloads a disguised binary (PHP extension), kills competing processes, and establishes persistence and a backdoor. Honeypots trapped attempts and prior reporting suggests widespread targeting; recommended mitigations include restricting and authenticating Docker Remote API access, avoiding privileged containers, patching, and following container security best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.