logo

Docker Swarm and K8s cryptojacking campaign (Campaign)

ID: edcffc26-d9d8-567e-b746-0d75ae290f49

STIX ID: report--edcffc26-d9d8-567e-b746-0d75ae290f49

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2024-09-23

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Datadog Security Research identified a cryptojacking campaign abusing misconfigured Docker and Kubernetes environments: attackers exploit exposed Docker Engine APIs to deploy cryptocurrency miners and follow-on payloads enabling lateral movement across Docker, Kubernetes, and SSH-exposed hosts, with hardcoded paths in payloads suggesting possible targeting of GitHub Codespaces compute infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.