Malware Exploits 9Hits, Turns Docker Servers into Traffic Boosted Crypto Miners
ID: b5f831ff-6db6-5a4e-99d2-142fbde42bd7
STIX ID: report--b5f831ff-6db6-5a4e-99d2-142fbde42bd7
Feed Name: HackRead
Threat Score
Cado Security researchers observed a campaign targeting vulnerable Docker servers that deploys two containers: an XMRig cryptocurrency miner and the 9Hits headless-browser viewer for automated traffic exchange. Attackers use scripts to set DOCKER_HOST, fetch images from Docker Hub, and run a custom nh.sh entrypoint with session tokens to authenticate the 9Hits app, enabling click-fraud while exhausting host CPU and potentially leaving remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
