Attackers deploying new tactics in campaign targeting exposed Docker APIs
ID: 5f1a2245-a449-50fe-acfd-b040b5a07126
STIX ID: report--5f1a2245-a449-50fe-acfd-b040b5a07126
Feed Name: Datadog Security Labs
Datadog Security Labs details a live cryptojacking campaign targeting unauthenticated Docker Engine hosts that deploys new and updated payloads (vurl, chkstart, exeremo, top) to escape containers via bind mounts and chroot, persist by modifying systemd ExecStartPost entries, establish SSH backdoors, scan for additional targets, and run a bundled XMRig miner; the report includes comprehensive TTPs and IoCs (filepaths, domains, IPs, SHA256 hashes) for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
