HomeSecurityDocker malware targets exposed APIs

Docker malware targets exposed APIs

A new malware variant, first reported in June 2025, has evolved to target exposed Docker APIs, rather than relying on Docker evasion techniques as previously. According to security researchers from Akamai ’s Hunt team , the new variant has also shifted its focus to creating backdoors and persistence, along with attempts to block API access to competitors.

See also: Docker Desktop Windows: Vulnerability leads to system compromise

Docker malware

“The new variant was last observed in August 2025 in Akamai’s honeypot infrastructure,” said Yonathan Gilvarg, a senior security researcher on Akamai’s Hunt team, in a blog post. The variant is based on a variant reported by Trend Micro in June, but differs in both binary payloads and initial access methods, Gilvarg noted.

The key infection factors here are misconfigured Docker APIs exposed to the internet, typically on port 2375.Attackers use these to launch a container, mount the computer's file system, and then execute Base64-encoded scripts retrieved via Tor. These scripts, in their first stage, install tools such as curl, tor, and bulk scanning tools, and then in the second stage, download and execute malicious components.

See also: Hackers steal crypto via misconfigured Docker APIs

Docker malware targets exposed APIs

Once inside, the malware initiates various containment and evasion measures, which include adding a malicious SSH public key to the root user's authorized keys, creating cron jobs, and customizing computer directories to maintain visibility and control.

Common practices that can leave Docker APIs exposed to public access include running the Docker API without Transport Layer Security (TLS) for convenience, connecting to 0.0.0.0 instead of localhost, cloud deployments with weak firewall rules, and using third-party orchestration or monitoring tools that require constant access to the Docker API.

What sets the variant apart is its move to deny others access to the same Docker API, essentially monopolizing the attack surface. It attempts to modify firewall settings via a cron job to reject incoming connections on port 2375. A cron job is a scheduled task on Linux systems that runs automatically at specified times or intervals.

See also: New self-propagating malware infects Docker Containers

Docker malware targets exposed APIs

Akamai warns that while these capabilities are not yet fully exploited, their presence suggests that the malware could evolve into a more complex botnet.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS