Cryptojacking Campaign Targets Misconfigured Kubernetes Clusters
ID: ed57c8f9-39d9-5c98-b0b1-89a906e635e4
STIX ID: report--ed57c8f9-39d9-5c98-b0b1-89a906e635e4
Feed Name: The Hacker News
Threat Score
Researchers report an ongoing cryptojacking campaign targeting misconfigured, Internet-facing Kubernetes API servers with anonymous authentication enabled; attackers launch malicious Docker images (some with 10,000+ pulls) and deploy benign‑looking DaemonSets to run a UPX-packed DERO miner (named "pause") across cluster nodes, hard‑coding wallet and pool settings and using obfuscation and supporting tools to evade detection and remove competing miners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
