In recent years, Docker services have become a target for malicious actors looking for innovative ways to exploit their vulnerabilities. A recent discovery by cloud security firm Cado reveals a new Docker malware campaign that uses a dual approach, exploiting the cryptocurrency miner XMRig and the software 9Hits Viewer . This represents a significant shift in the tactics used by adversaries, demonstrating their continued efforts to diversify their strategies and capitalize on compromised servers .
See also: OracleIV DDoS Botnet Malware Targets Docker Engine API Instances

A compelling feature of this campaign is the use of the 9Hits app as a payload. Billed as a “unique web traffic solution,” 9Hits is presented as an “automated traffic exchange” where members can increase their website traffic by earning credits through an object-oriented Chromecalled the 9Hits Viewer. This development highlights the adaptability of malicious actors, who are always looking for new ways to exploit compromised systems.
Although the exact method of spreading the malware to vulnerable Docker servers remains unclear, it is suspected that search engines such as Shodan are used to identify potential targets. Once identified, the servers are hijacked to deploy two malicious containers via the Docker API, leveraging pre-built images from the Docker Hub library for the 9Hits and XMRig software.
Instead of choosing custom images, the malicious actors use generic images from Docker Hub, a common tactic in attacks targeting Docker. This technique ensures that generic images can be retrieved and used for the attackers’ purposes. By extracting a list of websites to visit and authenticating with 9Hits using the session token, the 9Hits container executes code to generate credits. At the same time, the XMRig miner, located in another container, connects to a private mining pool, masking the scale and profitability of the campaign.
See also: Who is the new AMBERSQUID cryptojacking campaign targeting?
For compromised hosts, this campaign has a broad impact. Resource exhaustion is a key issue, as XMRig hoards available CPU and 9Hits consumes significant bandwidth and memory. On compromised servers, legitimate expert workloads experience performance issues that prevent normal operation. In addition, there is the potential for more serious breaches, as the attack campaign can evolve and leave a remote shell on the system, increasing the risk of unauthorized access.

Protecting Docker environments from evolving threats, such as the Docker malware campaign discussed above, is more than important. As attackers continue to adapt and change their tactics, staying informed and implementing reliable security measures is critical. Organizations must remain vigilant, update and patch their systems regularly, and implement security best practices to harden their Docker environments against emerging threats.
See also: TeamTNT's Cloud Credential Theft Campaign Now Targets Azure and Google Cloud
How can we identify and prevent malware attacks?
Identifying malware attacks requires paying attention to signs that may indicate that a system has been infected. These signs can include unexpected changes in computer, such as increased CPU usage, unexpected changes to settings, or even loss of mouse or keyboard control.
To prevent malware attacks, it is important to keep your software and operating system up to date. These updates often include security fixes that can prevent malware from executing. It is also important to use a reputable anti-malware program, which should also be up to date.
Additionally, educating users about the tactics attackers use to distribute malware can help prevent attacks. This can include learning how to recognize phishing attacks, avoiding downloading files from untrusted sources, and avoiding suspicious links.
Finally, using firewalls and other network security tools can help protect against malware attacks. These tools can monitor network traffic for abnormal behavior that may indicate an attack and block traffic that appears suspicious.
Source: securityboulevard
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
