logo

Attackers deploying new tactics in campaign targeting exposed Docker APIs

ID: 5f1a2245-a449-50fe-acfd-b040b5a07126

STIX ID: report--5f1a2245-a449-50fe-acfd-b040b5a07126

Feed Name: Datadog Security Labs

Threat Score
72/100

Date Published: 2024-06-13

Date Updated: 2026-04-27

...
...

Datadog Security Labs details a live cryptojacking campaign targeting unauthenticated Docker Engine hosts that deploys new and updated payloads (vurl, chkstart, exeremo, top) to escape containers via bind mounts and chroot, persist by modifying systemd ExecStartPost entries, establish SSH backdoors, scan for additional targets, and run a bundled XMRig miner; the report includes comprehensive TTPs and IoCs (filepaths, domains, IPs, SHA256 hashes) for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.