logo

Cryptocurrency Miners Abusing Containers: Anatomy of an Attack

ID: d1f5feea-250d-5bd2-9b14-114466c338ae

STIX ID: report--d1f5feea-250d-5bd2-9b14-114466c338ae

Feed Name: Aqua Security Blog

Threat Score
45/100

Date Published: 2018-02-15

Date Updated: 2026-04-26

...
...

This report describes a honeypot study of automated attackers scanning for exposed Docker daemons and attempting to deploy Monero cryptocurrency miners. The adversary probed the Docker API to identify versioning, tried multiple image injection techniques (docker import, docker build, and pulling public miner images), and repeatedly attempted to create and start mining containers; all runtime attempts were blocked by Aqua CSP, allowing observation of attacker behavior without system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.