
Launched on Nov. 24, a new cryptojacking campaign uses Docker platforms that have API endpoints exposed online to mine XMR.
A group of hackers has launched a new cryptojacking campaign on Nov. 24, scanning as many as 59,000 IP networks to find Docker platforms that have API endpoints exposed online, business technology publication ZDNet reports Nov. 26.
According to the report, the campaign is targeting vulnerable Docker instances in order to deploy crypto-malware to generate funds for the hacking group by mining Monero (XMR).
The mass scanning issue was first discovered by American internet security firm Bad Packets LLC on Nov. 25.
Troy Mursch, chief research officer and co-founder of Bad Packets LLC, said that exploit activity targeting exposed Docker instances is not new and happens quite often. In March 2018, cybersecurity company Imperva reported that 400 Docker servers — which were remotely accessible through an API weakness — contained Monerno mining programs.
Hackers used a “classic” XMR crypto miner
Mursch, who reportedly discovered the campaign, told ZDNet that once the hacking group manages to identify an exposed host, attackers deploy the API endpoint to start an Alpine Linux OS container to run a command that downloads and runs a Bash script from the attackers’ server. That script then reportedly installs a “classic XMRRig cryptocurrency miner.”
According to Mursch, hackers mined 14.82 XMR in the two days the Docker-targeting campaign has been active, which is worth $835 at press time.
Docker is a developer tool designed to simplify processes of creating, deploying and running software by using containers. Containers allow developers to package up an application with all of the required parts like libraries and other dependencies and deliver it as one package.
In order to avoid the newly detected vulnerability, Mursch recommends that users who run Docker instances immediately check if they are exposing their API endpoints on the internet, close the ports, and terminate unrecognized running containers.
On Nov. 25, major crypto exchange BitBay announced that the platform will delist Monero due to money laundering concerns. BitBay follows other exchanges like OKEx, who have delisted the cryptocurrency in order to remain compliant with guidelines set by the Financial Action Task Force.
Source: , CoinTelegraph

Articles listed with Cash Tech News as the author are either general information, or may have been imported from another website, to bring our readers a rich media experience that encompasses articles that we find interesting, as well as those curated by others.
The views and opinions expressed here are for informational purposes only, and should not be confused with professional financial advice. These opinions are solely those of the author and do not necessarily reflect the views of CashTechNews.com. Every investment and trade involves risk. You should conduct your own research, and contact your professional financial advisor before making any investment.
Corrections, feedback, and ideas should be submitted through the website contact form.