logo

Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances

ID: eb883c3a-d47c-5e19-8e5a-3cbb3ca89b8e

STIX ID: report--eb883c3a-d47c-5e19-8e5a-3cbb3ca89b8e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-07

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Trend Micro researchers report an active cryptojacking campaign by the actor 'Commando Cat' that targets misconfigured Docker remote APIs to deploy a cmd.cat/chattr image, escape the container using chroot, and download a miner (suspected ZiggyStarTux) from a C2 domain; separately, Akamai documents exploitation of older ThinkPHP CVEs by a suspected Chinese-speaking actor to deploy a Chinese-language Dama web shell for persistent control and post-exploitation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.