New Docker Malware Steals CPU for Crypto & Drives Fake Website Traffic
ID: 9ee6e540-58b4-56bf-82bf-3ec7575c383e
STIX ID: report--9ee6e540-58b4-56bf-82bf-3ec7575c383e
Feed Name: The Hacker News
Threat Score
The report describes a campaign abusing vulnerable Docker services to deploy two containerized payloads: an XMRig monero miner connected to a private pool and a 9Hits Viewer instance used for automated traffic/click-fraud. Attackers appear to scan for exposed Docker APIs (likely via Shodan), pull generic images from Docker Hub, and run containers that exhaust CPU, memory, and bandwidth on compromised hosts; the use of a private mining pool obscures the campaign's scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
