Threat Alert: Attackers Building Malicious Images Directly on Your Host
ID: 4aa99c33-a709-51bc-a464-606167959a4b
STIX ID: report--4aa99c33-a709-51bc-a464-606167959a4b
Feed Name: Aqua Security Blog
Threat Score
**Executive summary:** Team Nautilus discovered an active attack against misconfigured Docker APIs in which an attacker used the Docker Python SDK to build a container image directly on the target host, downloaded a shell script and an XMRIG cryptominer from 185.10.68.147, and executed the miner to hijack host resources—this technique evades static image/registry defenses and underscores the need for dynamic threat analysis and runtime scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
