logo

Exposed Docker APIs Under Attack in 'Commando Cat' Cryptojacking Campaign

ID: 4be1443d-fb89-598b-a2dc-6bcfc508122e

STIX ID: report--4be1443d-fb89-598b-a2dc-6bcfc508122e

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-02-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Commando Cat is an active cryptojacking campaign targeting exposed Docker API endpoints that deploys a seemingly benign container, escapes to the host using chroot, and drops multiple payloads to establish persistence, backdoor the host, exfiltrate cloud credentials, and run an XMRig cryptocurrency miner; the campaign uses evasion techniques (e.g., /dev/shm and Base64-encoded scripts) and shows overlap with prior cryptojacking groups like TeamTNT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.