Crypto-Mining Malware Outsmarting Image Scanners
ID: 9ccc2c65-c633-55b7-b7d4-7d3a6f2cfd97
STIX ID: report--9ccc2c65-c633-55b7-b7d4-7d3a6f2cfd97
Feed Name: Aqua Security Blog
Threat Score
The report describes crypto-mining malware distributed as Docker images that evolved from clear-text payloads to a more evasive variant which embeds a gzip-compressed, base64-encoded toolset inside ELF binaries to hide scripts from image scanners; it documents the unpack/decode sequence, shows how the miner and propagation components run, and recommends runtime controls such as image-to-container drift prevention to detect and block these obfuscated payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
