logo

Multi-Layered Cryptojacking via Docker (Campaign)

ID: 199b0d31-cdcd-55b1-83dc-63c0ef41f6c3

STIX ID: report--199b0d31-cdcd-55b1-83dc-63c0ef41f6c3

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2025-04-22

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A cryptojacking campaign distributing a malicious Docker Hub image (kazutod/tene:ten) runs a heavily obfuscated Python payload that requires over 60 decoding iterations before executing. The final payload abuses the Web3 rewards platform teneo.pro by sending heartbeat pings to earn tokens instead of contributing legitimate data, demonstrating a shift toward stealthy, multi-layered abuse of legitimate services for illicit profit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.