logo

Gafgyt Malware Targeting Misconfigured Docker Servers (Campaign)

ID: 534c8aa6-0c2b-5376-98df-0cd73e4b6713

STIX ID: report--534c8aa6-0c2b-5376-98df-0cd73e4b6713

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-12-03

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed threat actors leveraging misconfigured Docker Remote API servers to create containers (often from the alpine image), mount the host filesystem, escalate privileges, and deploy Gafgyt malware variants (e.g., rbot, atlas.i586). The campaign uses shell scripts (including a fallback cve.sh) to fetch multi-architecture binaries that connect to hardcoded C2 servers and carry out DDoS attacks using UDP, TCP, ICMP, HTTP, and SYN vectors, representing a shift from IoT-only targeting to abusing cloud/container misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.