Get a Demo

news

Breaking Cyber News From Cyberint

Breaking news feed of the latest cyber incidents, breaches, vulnerabilities, malware, ransomware and so much more.

  • May 28, 2025

    • North America
    • Resource Hijacking
    • Ingress Tool Transfer
    • Remote System Discovery
    • Unix Shell
    • Obfuscated Files Or Information
    • Network Service Discovery
    • Deploy Container
    • Escape To Host
    • Docker
    • Match Legitimate Name Or Location
    • Change Default File Association
    • United States
    • Lateral Tool Transfer
    • Exploitation For Client Execution
    • Business Services
    • Smb/Windows Admin Shares
    • Exploit Public-Facing Application
    • Web Protocols
    • External Remote Services

    Cryptojacking Campaign Targets Misconfigured Docker APIs

    A new malware campaign has emerged, targeting misconfigured Docker API instances to create a cryptocurrency mining botnet focused on mining Dero currency. The threat actor exploits insecurely published Docker APIs to gain access to running containerized infrastructures, propagating the malware through a worm-like mechanism to infect other exposed Docker instances. The attack utilizes two main components: a propagation malware named 'nginx' that scans for vulnerable Docker APIs, and a 'cloud' Dero cryptocurrency miner. This campaign has been linked to previous cryptojacking operations and poses a significant risk to any network with insecure Docker APIs.

Ready to
experience hyper-relevance?

See Argos Edge in action!

Schedule a demo

Uncover your compromised credentials from the deep and dark web

Fill in your business email to start