Threat Alert: Exploiting Open Docker Daemons for DDoS Attacks
ID: 875bc080-9738-59eb-81a5-e158d78c65b0
STIX ID: report--875bc080-9738-59eb-81a5-e158d78c65b0
Feed Name: Aqua Security Blog
Threat Score
This report details two DDoS campaigns in which attackers exploited misconfigured open Docker daemons to deploy containerized botnets using modified udpflood and slowhttptest binaries; the analysis covers binary comparisons to open-source versions, attack chain (scanning, image creation/upload, remote deployment), targeting of Alibaba Cloud hosts, and provides IOCs and mitigation advice to secure Docker daemons and enforce image assurance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
