Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances
ID: eb883c3a-d47c-5e19-8e5a-3cbb3ca89b8e
STIX ID: report--eb883c3a-d47c-5e19-8e5a-3cbb3ca89b8e
Feed Name: The Hacker News
Threat Score
Trend Micro researchers report an active cryptojacking campaign by the actor 'Commando Cat' that targets misconfigured Docker remote APIs to deploy a cmd.cat/chattr image, escape the container using chroot, and download a miner (suspected ZiggyStarTux) from a C2 domain; separately, Akamai documents exploitation of older ThinkPHP CVEs by a suspected Chinese-speaking actor to deploy a Chinese-language Dama web shell for persistent control and post-exploitation activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
