logo

'Commando Cat' Digs Its Claws Into Exposed Docker Containers

ID: 3eed4cc1-4bdc-560b-9f05-3e13ad6e6233

STIX ID: report--3eed4cc1-4bdc-560b-9f05-3e13ad6e6233

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-06-06

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Commando Cat is an active cryptojacking campaign exploiting misconfigured Docker remote API servers: attackers deploy benign containers, use chroot and volume binding to escape containers to the host, establish C2, and install cryptocurrency miners. Trend Micro and Cado Security recommend using only official images, avoiding running containers as root, performing regular security audits, and ensuring Docker APIs are not exposed to the Internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.