logo

Crypto-Mining Malware Outsmarting Image Scanners

ID: 9ccc2c65-c633-55b7-b7d4-7d3a6f2cfd97

STIX ID: report--9ccc2c65-c633-55b7-b7d4-7d3a6f2cfd97

Feed Name: Aqua Security Blog

Threat Score
60/100

Date Published: 2019-07-08

Date Updated: 2026-04-26

...
...

The report describes crypto-mining malware distributed as Docker images that evolved from clear-text payloads to a more evasive variant which embeds a gzip-compressed, base64-encoded toolset inside ELF binaries to hide scripts from image scanners; it documents the unpack/decode sequence, shows how the miner and propagation components run, and recommends runtime controls such as image-to-container drift prevention to detect and block these obfuscated payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.