logo

Malware Exploits 9Hits, Turns Docker Servers into Traffic Boosted Crypto Miners

ID: b5f831ff-6db6-5a4e-99d2-142fbde42bd7

STIX ID: report--b5f831ff-6db6-5a4e-99d2-142fbde42bd7

Feed Name: HackRead

Threat Score
65/100

Date Published: 2024-01-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Cado Security researchers observed a campaign targeting vulnerable Docker servers that deploys two containers: an XMRig cryptocurrency miner and the 9Hits headless-browser viewer for automated traffic exchange. Attackers use scripts to set DOCKER_HOST, fetch images from Docker Hub, and run a custom nh.sh entrypoint with session tokens to authenticate the 9Hits app, enabling click-fraud while exhausting host CPU and potentially leaving remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.