HomeSecurityOracleIV DDoS Botnet Malware Targets Docker Engine API Instances

OracleIV DDoS Botnet Malware Targets Docker Engine API Instances

The OracleIV botnet malware uses various tactics, with a primary focus on executing DDoS attacks via UDP and SSL-based floods.

OracleIV DDoS Botnet Malware Targets Docker Engine API Instances

Cybersecurity researchers at Cado Security Labs have uncovered a new DDoS (Distributed Denial of Service) botnet malware named OracleIV, which targets publicly exposed Docker Engine API instances.

The findings are part of an investigation into a malicious campaign that exploits misconfigurations in Docker containers to deliver Python malware, compiled as an ELF executable.

Recently, Docker Engine APIs have become a frequent target for cybercriminals, as the method has gained popularity due to the increasing adoption of microservices architectures. Hackers exploit the inadvertent exposure of the Docker Engine API, often detecting vulnerable environments to deliver malicious payloads with nefarious objectives.

In the case of the new OracleIV DDoS botnet malware, attackers initiate access with an HTTP POST request to the Docker API, specifically the /images/create endpoint. This triggers a docker pull command, which retrieves a specific icon from Dockerhub. Once the malicious image is retrieved, a container is launched to carry out the attacker’s purposes.

Cado Security researchers discovered a live Dockerhub page for an image named “oracleiv_latest” uploaded by user “robbertignacio328832. The image, seemingly harmless as a “Mysql image for docker,” included a malicious payload named “oracle.sh,” an ELF executable that acts as a DDoS bot agent. Further analysis revealed additional commands to retrieve XMRig and a miner configuration file.

Static analysis of the executable revealed a 64-bit ELF compiled with Cython, confirming the Python origin of the OracleIV malware. The malware code, short but powerful, includes several functions related to various DDoS methods.

OracleIV DDoS Botnet

The bot connects to a Command and Control (C2) server, performing basic authentication with a hardcoded password. Cado Security Labs monitored the botnet's activity, recording DDoS attacks on various targets, using UDP and SSL-based floods.

C2 commands for launching DDoS attacks follow a specific format, specifying the type of attack, target IP/domain, attack duration, rate, and target port.

While OracleIV is not a supply chain attack, it demonstrates the ongoing risk of misconfiguration of Docker Engine API deployments. The portability of containerization allows hackers to execute malicious payloads continuously on Docker hosts.

Although Cado Security has reported the malicious user to Docker, users are urged to perform periodic assessments of images pulled from Dockerhub, emphasizing the need to be vigilant against malicious code.

In conclusion, the OracleIV campaign emphasizes the importance of securing web services and implementing strong network defenses. Users of Docker and similar services are encouraged to regularly check their exposure and take the necessary precautions against potential cyber threats.

Information source: hackread.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS