Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances

An ongoing cryptojacking assault effort that uses shoddy security Docker instances to deploy cryptocurrency miners for profit has been connected to the threat actor Commando Cat.

The payload is retrieved from the attackers’ own command-and-control (C&C) infrastructure via the cmd.cat/chattr docker image container, according to an analysis released on Thursday by Trend Micro researchers Sunil Bharti and Shubham Singh.

Initially reported by Cado Security earlier this year, Commando Cat gets its name from the fact that it creates a benign container using the open-source Commando project.

The attacks are typified by the use of misconfigured Docker remote API servers to launch the cmd.cat/chattr Docker image read more Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *