Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

TON Price Prediction: $1.50 Target as Technical Indicators Signal Potential 13% Rally

May 2, 2026

The Cheap Foreign Labor Regime Blocking Agricultural Intelligence

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Crypto-Mining Botnet Goes After Misconfigured Docker APIs
Crypto-Mining Botnet Goes After Misconfigured Docker APIs
Security

Crypto-Mining Botnet Goes After Misconfigured Docker APIs

November 2, 2023No Comments2 Mins Read

A notorious cryptocurrency mining botnet has begun targeting misconfigured Docker APIs, according to CrowdStrike.

LemonDuck has been observed exploiting ProxyLogon vulnerabilities in Microsoft Exchange Server and using EternalBlue and other exploits to mine cryptocurrency, escalate privileges and move laterally inside compromised networks.

Now its attention has turned to one of the world’s most popular containerization platforms.

The botnet is targeting exposed Docker APIs in order to gain initial access, CrowdStrike explained.

“It runs a malicious container on an exposed Docker API by using a custom Docker Entrypoint to download a ‘core.png’ image file that is disguised as Bash script,” it said in a blog post yesterday.

Before the payload – an “a.asp” file – is downloaded and mining can begin, it performs several actions, including killing the processes, IOC file paths and C&C connections of competing crypto-mining groups.

The a.asp file also has the capability to switch off Alibaba’s cloud monitoring service in order to fly under the radar of network defenders.

LemonDuck attempts to move laterally by searching for SSH keys on a filesystem, using them to log into additional servers and run its malicious scripts.

The researchers also found multiple campaigns running from many of the C&C servers associated with LemonDuck, including ones targeting Windows and Linux machines.

“Due to the cryptocurrency boom in recent years, combined with cloud and container adoption in enterprises, cryptomining is proven to be a monetarily attractive option for attackers,” CrowdStrike concluded.

“Since cloud and container ecosystems heavily use Linux, it drew the attention of the operators of botnets like LemonDuck, which started targeting Docker for cryptomining on the Linux platform.”

See also  Robbery Shock for Binance’s France Head, Three Suspects Detained! Here Are the Details

The campaign highlights the need for administrators to ensure their container environments are correctly configured according to industry best practices, and ideally with cloud workload security and detection and response tools installed.

Source link

APIs Botnet Cryptomining Docker Misconfigured

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Bitcoin's rally faces key hurdle with Wednesday's Fed meeting

March 17, 2026

Tether Carries Out Its Largest Asset Freeze to Date – Two Wallets Holding $344 Million Frozen

April 25, 2026

Phemedrone Stealer Targets Windows Defender Flaw Despite Patch

March 15, 2026

Type above and press Enter to search. Press Esc to cancel.