New Cryptojacking Campaign Targets Exposed Docker APIs
ID: b853e861-013d-5598-8773-3958b1f0d51d
STIX ID: report--b853e861-013d-5598-8773-3958b1f0d51d
Feed Name: securityonline.info
Datadog Security Labs describes a cryptojacking campaign that scans for Docker Engine hosts with the Docker API exposed (port 2375), abuses the API to spawn containers bound to the host filesystem, and deploys new binaries (chkstart, exeremo, and a Go ported vurl downloader) to maintain persistence, spread via SSH, and fetch an XMRig miner. The report highlights novel persistence by appending ExecStartPost to systemd unit files, lateral movement capabilities, and provides IoCs and recommended mitigations such as closing unauthenticated Docker APIs, patching, access controls, and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
