TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs
Researchers studying cybersecurity have found a variation of a recently revealed campaign that targets unprotected Docker APIs with cryptojacking assaults by abusing the TOR network.
According to Akamai, which uncovered the most recent activity last month, its purpose is to prevent other actors from using the Docker API online.
The discoveries expand upon a previous investigation from Trend Micro in late June 2025 that discovered a malicious campaign that used a TOR domain for anonymity to covertly drop an XMRig bitcoin miner on vulnerable Docker instances.
According to researcher Yonatan Gilvarg, this new infection may have a different end purpose, such as laying the groundwork for a sophisticated botnet security system, even if it appears to employ similar tools to the original...

