HomeSecurityGraboid: New cryptojacking worm found on Docker hosts

Graboid: New cryptojacking worm found on Docker hosts

Researchers from Unit 42 have uncovered a new cryptojacking worm called 'Graboid' that has spread to over 2000 unsecured Docker hosts.

More details about the worm

Researchers noted that Graboid is the first cryptojacking virus to spread using containers on the Docker Engine.

  • The attackers behind Graboid gained an initial foothold through unsecured Docker hosts, where a Docker image was first installed.
  • After that, the cryptojacking virus is deployed for Monero mining.
  • Meanwhile, the worm periodically checks for new vulnerable hosts from the C&C server and randomly selects the next target.

cryptojacking worm

The docker image 'pocosow/centos' contains a docker client tool used to communicate with other Docker hosts. In addition, 'pocosow/centos' is used to download a set of four scripts from the C&C server and execute them.

The four scripts include:

  • 'Live.sh' – This shell script sends the number of available processors on the compromised host to the C&C server.
  • Worm.sh' – This shell script downloads an “IP” file containing a list of 2000+ IPs, selects random IPs as targets, and uses the docker tool to pull and deploy the POSOSOW / centos container remotely.
  • 'cleanxmr.sh' – This script stops cryptojacking containers and other xmrig-based containers on the target.
  • 'xmr.sh' – This selects random vulnerable hosts from the IP file and transforms the gakeaws/nginx image on the target host.

The researchers noted that the docker image 'pocosow/centos' has been downloaded more than 10,000 times and 'gakeaws/nginx' has been downloaded more than 6,500 times.

It is worth noting

  • The researchers concluded that it takes about 60 minutes for the worm to reach all 1,400 vulnerable hosts.
  • On average, there are almost 900 active miners at any given time.
  • On average, each miner is active 63% of the time and each mining session lasts 250 seconds.

The researchers' recommendations

  • The researchers recommend that organizations never expose a docker daemon to the Internet without authentication.
  • They suggest organizations periodically check for any unknown containers or images on the system.
  • It is always better to use Unix socket to communicate locally with the Docker daemon or use SSH to connect to a remote docker daemon.
  • It is recommended that you use firewall rules to flag incoming traffic to a small set of sources.

"While this cryptojacking virus does not involve sophisticated tactics, techniques, or processes, the worm can periodically pull new scripts from the C2s, so it can easily transform into ransomware or any malware to completely compromise hosts down the line. If a more powerful worm is created to follow a similar penetration, it could cause much greater damage, which is why it is imperative that organizations protect Docker hosts," the researchers concluded.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS