logo

New Cryptojacking Campaign Targets Exposed Docker APIs

ID: b853e861-013d-5598-8773-3958b1f0d51d

STIX ID: report--b853e861-013d-5598-8773-3958b1f0d51d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-06-17

Date Updated: 2026-04-22

Author: do son

...
...

Datadog Security Labs describes a cryptojacking campaign that scans for Docker Engine hosts with the Docker API exposed (port 2375), abuses the API to spawn containers bound to the host filesystem, and deploys new binaries (chkstart, exeremo, and a Go ported vurl downloader) to maintain persistence, spread via SSH, and fetch an XMRig miner. The report highlights novel persistence by appending ExecStartPost to systemd unit files, lateral movement capabilities, and provides IoCs and recommended mitigations such as closing unauthenticated Docker APIs, patching, access controls, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.