Hackers are targeting remote API Docker Servers to deploy the SRBMiner crypto miner, according to new findings from Trend Micro.

Researchers Abdelrahman Esmail and Sunil Bharti reported in a technical report that hackers are exploiting the gRPC protocol via h2c to bypass security measures and conduct cryptocurrency mining on Docker hosts.
See more: Crypto theft campaign has infected 28,000 people
The hacker first checks the availability and version of the Docker API, followed by requests for gRPC/h2c upgrades as well as gRPC methods related to managing Docker environments, such as health checks and secret management. Once the server accepts the upgrade, a gRPC request is sent to create containers and mine XRP using SRBMiner.
Researchers note that the malicious agent bypasses multiple layers of security, facilitating illegal cryptocurrency. At the same time, Trend Micro has observed hackers exploiting remote exposed Docker servers to deploy the perfctl malware. This campaign involves scanning public servers and creating Docker containers with the image “ubuntu:mantic-20240405”.

Read more: Cryptojacking: The new threat to computers
Users are advised to protect their remote Docker API servers through strong access controls, monitor for unusual activity, and implement container security best practices to prevent unauthorized access.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
