logo

Threat Alert: Exploiting Open Docker Daemons for DDoS Attacks

ID: 875bc080-9738-59eb-81a5-e158d78c65b0

STIX ID: report--875bc080-9738-59eb-81a5-e158d78c65b0

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-01-20

Date Updated: 2026-05-12

...
...

This report details two DDoS campaigns in which attackers exploited misconfigured open Docker daemons to deploy containerized botnets using modified udpflood and slowhttptest binaries; the analysis covers binary comparisons to open-source versions, attack chain (scanning, image creation/upload, remote deployment), targeting of Alibaba Cloud hosts, and provides IOCs and mitigation advice to secure Docker daemons and enforce image assurance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.