'Commando Cat' Digs Its Claws Into Exposed Docker Containers
ID: 3eed4cc1-4bdc-560b-9f05-3e13ad6e6233
STIX ID: report--3eed4cc1-4bdc-560b-9f05-3e13ad6e6233
Feed Name: Dark Reading
Threat Score
Commando Cat is an active cryptojacking campaign exploiting misconfigured Docker remote API servers: attackers deploy benign containers, use chroot and volume binding to escape containers to the host, establish C2, and install cryptocurrency miners. Trend Micro and Cado Security recommend using only official images, avoiding running containers as root, performing regular security audits, and ensuring Docker APIs are not exposed to the Internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
