HomeSecurityCommando Cat Cryptojacking Targets Docker Instances

Commando Cat Cryptojacking Targets Docker Instances

The threat actor known as Commando Cat has been linked to an ongoing cryptojacking attack campaign that exploits unsecured Docker instances to mine cryptocurrencies for financial gain.

commando cat cryptojacking

"The attackers used the Docker image container cmd.cat/chattr, which retrieves the payload from their command and control (C&C) infrastructure," Trend Micro researchers Sunil Bharti and Shubham Singh said in their analysis on Thursday.

See also: FBI: Using unlicensed crypto services leads to financial losses

Commando Cat, named after its use of the open source Commando project to create a malicious container, was first documented this year by Cado Security.

The attacks are characterized by targeting poorly configured Docker servers with remote APIs to deploy a Docker image named cmd.cat/chattr. This image is then used as the basis for creating a container, which bypasses its restrictions by using the chroot command to gain access to the host operating system.

The final step involves retrieving the malicious miner binary via a curl or wget command from a C&C server (“leetdbs.anndns[.]net/z”), via a shell script. The binary is believed to be ZiggyStarTux, an open-source IRC bot based on the Kaiten (also known as Tsunami) malware

“The significance of this attack campaign lies in the use of Docker images to deploy cryptocurrency mining scripts on compromised systems,” the researchers said. “This tactic allows attackers to exploit vulnerabilities in Docker configurations, avoiding detection by security software.”

See more: Scammers target Telegram users and steal Toncoins

The revelation comes as Akamai revealed that older security flaws in ThinkPHP applications (such as CVE-2018-20062 and CVE-2019-9082) are being exploited by a suspected Chinese-speaking threat actor to install a web shell called Dama as part of a campaign that has been ongoing since October 17, 2023.

“The exploit attempts to retrieve additional obfuscated code from another compromised ThinkPHP server to gain an initial foothold,” Akamai researchers Ron Mankivsky and Maxim Zavodchik said. “After successfully exploiting the system, the attackers install a Chinese-language web shell, known as Dama, to maintain persistent access to the server.”

The web shell has a wealth of advanced capabilities, such as system data collection, file uploads, network scanning, privilege escalation, and file system navigation. These capabilities are often used for the purpose of hiding activities.

commando cat cryptojacking

Read more: Which personality traits make us more vulnerable to phishing

“Recent attacks by Chinese-speaking adversaries demonstrate a growing trend of hackers using fully-fledged web shells for advanced control of victims,” the researchers noted. “Interestingly, not all targeted customers were using ThinkPHP, suggesting that attackers may be targeting a wide range of systems.”

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS