logo

Threat Alert: Attackers Building Malicious Images Directly on Your Host

ID: 4aa99c33-a709-51bc-a464-606167959a4b

STIX ID: report--4aa99c33-a709-51bc-a464-606167959a4b

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-07-15

Date Updated: 2026-04-26

...
...

**Executive summary:** Team Nautilus discovered an active attack against misconfigured Docker APIs in which an attacker used the Docker Python SDK to build a container image directly on the target host, downloaded a shell script and an XMRIG cryptominer from 185.10.68.147, and executed the miner to hijack host resources—this technique evades static image/registry defenses and underscores the need for dynamic threat analysis and runtime scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.