logo

Threat Actors leverage Docker Swarm and Kubernetes to mine cryptocurrency at scale

ID: 695623b6-ee3b-5a33-a426-4b737d20a799

STIX ID: report--695623b6-ee3b-5a33-a426-4b737d20a799

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2024-09-23

Date Updated: 2026-04-27

...
...

Datadog Security Research discovered an active cryptojacking campaign that exploits exposed Docker Engine APIs to deploy containers which mount host filesystems, execute init scripts, and install XMRig miners; the malware propagates laterally to Docker Swarm, Kubernetes (via the kubelet API), and SSH hosts, uses process-hiding via ld.so.preload, manipulates Docker Swarm to join actor-controlled clusters, and exfiltrates credentials from paths indicative of GitHub Codespaces. The report includes payload/script hashes, C2 domains and URLs (solscan.live and subdomains), one attributed IP (164.68.106.96), and analysis of TTPs with low-confidence discussion of links to TeamTNT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.