Cryptocurrency Miners Abusing Containers: Anatomy of an Attack
ID: d1f5feea-250d-5bd2-9b14-114466c338ae
STIX ID: report--d1f5feea-250d-5bd2-9b14-114466c338ae
Feed Name: Aqua Security Blog
This report describes a honeypot study of automated attackers scanning for exposed Docker daemons and attempting to deploy Monero cryptocurrency miners. The adversary probed the Docker API to identify versioning, tried multiple image injection techniques (docker import, docker build, and pulling public miner images), and repeatedly attempted to create and start mining containers; all runtime attempts were blocked by Aqua CSP, allowing observation of attacker behavior without system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
