DERO cryptojacking campaign (2024) (Campaign)
ID: 6ada39ef-cf80-5410-b6c8-c5b158c779da
STIX ID: report--6ada39ef-cf80-5410-b6c8-c5b158c779da
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-06-07
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Wiz Threat Research identified a DERO cryptojacking campaign that exploits Kubernetes clusters with anonymous API-server access to deploy UPX-packed miner containers from Docker Hub. The attackers use benign-sounding container names, hardcoded/encrypted wallet and mining pool details to evade detection, update repository images and domains to hide communications, and employ additional tools (dropper scripts, misconfiguration exploitation) to propagate and suppress competing miners, suggesting a persistent, adaptive operation across cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
