logo

New Docker Malware Steals CPU for Crypto & Drives Fake Website Traffic

ID: 9ee6e540-58b4-56bf-82bf-3ec7575c383e

STIX ID: report--9ee6e540-58b4-56bf-82bf-3ec7575c383e

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-01-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes a campaign abusing vulnerable Docker services to deploy two containerized payloads: an XMRig monero miner connected to a private pool and a 9Hits Viewer instance used for automated traffic/click-fraud. Attackers appear to scan for exposed Docker APIs (likely via Shodan), pull generic images from Docker Hub, and run containers that exhaust CPU, memory, and bandwidth on compromised hosts; the use of a private mining pool obscures the campaign's scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.