logo

Docker hosts hacked in ongoing website traffic theft scheme

ID: a390ec15-8326-5620-a8cf-22cf90929969

STIX ID: report--a390ec15-8326-5620-a8cf-22cf90929969

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-01-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A campaign targeting exposed Docker services deploys containers running an XMRig Monero miner and the 9hits traffic-exchange viewer to monetize compromised hosts. Attackers likely scan for vulnerable Docker APIs, pull seemingly benign images from Docker Hub, and run containers that exhaust CPU, memory, and bandwidth while hiding mining activity via a private pool and generating traffic credits through authenticated 9hits sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.