Malformed Docker instances are the target of a malicious campaign that leverages the Tor anonymity network to silently mine crypto in vulnerable environments. Through the use of Tor, attackers seek to hide their origins when installing mining software on compromised systems.
See also: BitoPro links Lazarus to $11 million crypto theft

According to cybersecurity firm Trend Micro, the attacks begin with a request from the IP address 198.199.72[.]27 to obtain a list of all containers on the system. If there are no active containers, the attacker creates a new one based on the “alpine” Docker image and mounts the “/hostroot” directory – the root directory (“/”) of the physical or virtual host system – as a volume within the container.
This behavior poses serious security risks, as it allows the container to access and modify files and directories on the host system, which can lead to a “container escape.”
The attackers then execute a carefully orchestrated sequence of actions, which includes executing a Base64-encoded shell script to install Tor inside the Docker container during its creation stage. The ultimate goal is to retrieve and execute a remote script from a .onion domain (“wtxqf54djhp5pskv2lfyduub5ievxbyvlzjgjopk6hxge5umombr63ad[.]onion”).
See also: CoinMarketCap hacked: Site visitors' crypto stolen
After the container is created, the shell script “docker-init.sh” is executed, which checks for the existence of the mounted directory “/hostroot” and then modifies the SSH system configuration, allowing remote access. This is achieved by enabling root login and adding an SSH key controlled by the attacker to the ~/.ssh/authorized_keys.

The attacker has also been spotted installing various tools, such as masscan, libpcap, zstd, and torsocks, beaconing information about the infected system to the command and control (C&C) server, and finally transferring an executable file that acts as a dropper for the XMRig crypto miner. Along with this, the necessary mining settings, wallet addresses, and mining pool.
The findings indicate a continuing trend of cyberattacks targeting poorly configured or poorly secured cloud environmentsfor the purpose of cryptocurrency mining (cryptojacking).
See also: DOJ: Seizure of crypto linked to “pig butchering” scams
Based on the above, we can conclude that cybercriminals are systematically exploiting weak security parameters in cloud infrastructures and containerization environments, such as Docker, to carry out crypto mining. This means that instead of directly stealing data or causing visible damage, they use the victim system's resources (CPU, memory, network) to mine cryptocurrencies — most commonly Monero (XMR) due to the anonymity it offers.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
