Docker Gatling Gun Campaign
Essential information
- Published
- 29/10/2024 13:51
- Modified
- 29/10/2024 13:57
- Tags
- 2024-10-26 2024-10-29 campaign cloud-native container security cryptomining docker docker hub docker swarm exposed-daemons malicious prochider sliver tsunami
- Related entities
- 11 observables, 1 intrusion sets (apt), 14 techniques (mitre), 2 malware
Description
Recent research has uncovered a new malicious campaign orchestrated by the notorious hacking group TeamTNT. This campaign exploits exposed Docker daemons to deploy Sliver malware, a cyber worm, and cryptominers, utilizing compromised servers and Docker Hub as infrastructure for spreading their malicious payloads. TeamTNT is leveraging native cloud capabilities by appending compromised Docker instances to a Docker Swarm and using Docker Hub to store and distribute their malware, aiming to rent out victim's computational resources to third parties for cryptomining operations.
External references
- https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/?utm_campaign=General+website&utm_medium=email&_hsenc=p2ANqtz-92AbUxDf890WmIltI9X2LhL0FpMu9OhPLNQDdxetpcr8SI9czknB4Dc_4xvXmgaLfujLJonLpOoavAi_VrNIvPqpT_HnHtUpkyemNm2rQ1rWKTnuY&_hsmi=330821549&utm_content=330821549&utm_source=hs_email
- https://otx.alienvault.com/pulse/6720e8610825425e5d5cee81