New Cryptojacking Attack Targets Docker API to Create Malicious Swarm Botnet
A fresh cryptojacking effort targeting the Docker Engine API has been discovered by cybersecurity researchers. Its objective is to co-opt the instances and use them to join a malicious Docker Swarm under the threat actor's control.
This gave the attackers the ability to "use Docker Swarm's orchestration features for command-and-control (C2) purposes," according to an investigation by Datadog researchers Andy Giron and Matt Muir.
The attacks use Docker to gain initial access to compromised containers in order to plant a bitcoin miner. They also retrieve and run additional payloads that migrate laterally to linked sites that are using SSH, Docker, or Kubernetes.
In particular, masscan and ZGrab—two Internet scanning tools—are used to find unprotected and unauthenticated Docker API ...

