Docker Swarm and K8s cryptojacking campaign (Campaign)
ID: edcffc26-d9d8-567e-b746-0d75ae290f49
STIX ID: report--edcffc26-d9d8-567e-b746-0d75ae290f49
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-09-23
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Datadog Security Research identified a cryptojacking campaign abusing misconfigured Docker and Kubernetes environments: attackers exploit exposed Docker Engine APIs to deploy cryptocurrency miners and follow-on payloads enabling lateral movement across Docker, Kubernetes, and SSH-exposed hosts, with hardcoded paths in payloads suggesting possible targeting of GitHub Codespaces compute infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
