
A Docker Hub account , named “ azurenql ,” that contained malicious images for mining Monero was recently discovered by researchers . The account in question has been around since October 2019.
Research found that the malicious actor behind the account earned 525.38 XMR, which is about 30,000 USD based on the current dollar price.
Docker offers operating system-level virtualization for delivering software in packages called containers. Dockers are popular these days, which has made them common targets for hackers looking to make money through cryptojacking.
Malicious Docker accounts
The researchers observed that a user account named “azurenql” contains eight repositories hosting six malicious Monero mining images.
The base images use the Ubuntu 16.04.6 LTS operating system.
In order to maintain their anonymity, the hackers used Tor.

To succeed in mining cryptocurrency, the attackers used two methods, running these malicious images in the user's environment.
The first method is to submit mined blocks directly to the central minexmr pool, using a wallet ID.
The second method is to use a hosting service that runs their mining pool, which is used for collecting mined blocks.
As observed by the researchers, the wallet ID is still used and the most recent mining activity was observed in April and May 2020.
Cryptomining attacks have become increasingly common. Malicious actors are compromising servers, personal computers, Chrome , and web portals to mine digital currencies like Monero. Security researchers at Unit42 were the first to discover the malicious activity and immediately reported it to Docker Hub. Any malicious accounts found were promptly deleted.
