logo

New Malware Targets Exposed Docker APIs for Cryptocurrency Mining

ID: 548de6a6-fbce-5566-a474-3fc000fd3dc7

STIX ID: report--548de6a6-fbce-5566-a474-3fc000fd3dc7

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-18

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Researchers reported a cryptojacking campaign abusing exposed Docker API endpoints (port 2375) and misconfigured services to deploy a multi-stage infection chain of shell scripts and Go binaries that provide remote access, lateral movement (exeremo), evasion (fkoths), and an XMRig miner; the campaign shows overlaps with the earlier 'Spinning YARN' activity and a shift toward Go-based payloads to complicate analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.