HomeSecurityNew Kinsing malware campaign targets Docker servers

New Kinsing malware campaign targets Docker servers

Docker servers

In recent months, a new malware campaign, has been underway scanning the internet for vulnerable Docker servers . Specifically , to identify servers with exposed API ports that are not protected by a password . Hackers then gain access to the vulnerable computers and install a new crypto-mining malware, called Kinsing .

The Kinsing malware attacks began last year but continue to this day. The malware campaign was discovered by security firm Aqua Security , which published a detailed description of it in a blog post on Friday.

There have been many other attacks that have targeted Docker systems, which, once compromised, provide hackers with unrestricted access to key components of the computer.

According to Gal Singer, a security researcher at Aqua, when hackers locate a Docker system with an exposed API port, they use the access provided by that port to launch an Ubuntu container, where they download and install the Kinsing malware.

The primary purpose of the malware is to steal cryptocurrency, but it also has some other functions. The Kinsing malware has scripts that remove other malware (which may be running locally), while also stealing SSH credentials, in an attempt to spread the malware across a company's container network and infect other cloud systems.

Kinsing malware

According to Aqua, Kinsing attacks are ongoing, so companies should review the security settings of their Docker servers and make sure there are no exposed APIs.

The recent Kinsing malware campaign is the latest in a long list of attacks targeting Docker servers with crypto-mining botnets.

The first attacks were observed in the spring of 2018 by Aqua and Sysdig.

Other attacks and malware have since followed. Other security companies, such as Trend Micro (October 2018, May 2019, June 2019), Juniper Networks (November 2018), Imperva (March 2019), Alibaba Cloud (May 2019), and Palo Alto Networks (October 2019), have discovered such attacks and published reports.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS