HomeSecurityExposed Docker APIs Continue to be Used for Cryptojacking

Exposed Docker APIs Continue to Be Used for Cryptojacking

docker

Earlier this year, it was reported that hackers were using insecure Docker and Kubernetes systems to create containers that were used for cryptomining. For those unfamiliar with containers, they are packages that contain an application and everything needed to run it. These packages can then be deployed as containers on Docker or Kubernetes systems.

Docker containers are deployed on a platform called Docker Engine, where they will run in the background alongside other containers deployed on the system. If the Docker Engine is not properly secured, attackers can remotely use the Docker Engine API to deploy containers of their own creation and use them on the system.

Trend Micro has recently identified an attacker who scans for exposed Docker Engine APIs and uses them to deploy containers that download and run a miner.

Once the container is installed and activated, it will launch an auto.sh script that will download a Monero miner and configure it to start automatically. The script will also download port scanning software, which will scan for other vulnerable Docker Engine instances on ports 2375 and 2376 and attempt to spread further.

To prevent attackers from exploiting insecure Docker Engine applications, Trend Micro recommends that administrators use the following security practices:

Strengthen security. The Center for Internet Security (CIS) has a reference that can help system administrators and security teams establish a baseline for securing the Docker engine.

Ensure that container images are certified, signed, and from a trusted registry (i.e. Docker Trusted Registry). Using automated image scanning tools helps improve development cycles.

Implement the principle of least privilege. For example, restrict access to the daemon and encrypt the communication protocols it uses to connect to the network. Docker provides instructions on how to secure the daemon socket.

Correctly configure how many resource containers are allowed to be used (control groups and namespaces).

Enable Docker's built-in security features to help defend against threats. Docker provides several guidelines on how to securely configure applications that rely on it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS