logo

'Commando Cat' Is Second Campaign of the Year Targeting Docker

ID: 380aedd3-f439-586a-97e9-ad985df3660e

STIX ID: report--380aedd3-f439-586a-97e9-ad985df3660e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-01

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Commando Cat is an active, sophisticated cryptojacking campaign abusing exposed Docker API endpoints to mount host filesystems and run payloads on the host; it combines a cryptocurrency miner with credential-stealing and backdoor capabilities, demonstrates strong evasion and redundancy, and shows overlaps with known tooling/IPs associated with groups like Team TNT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.