216.73.217.22

Dero miner spreads inside containerized Linux environments

· Published 21/05/2025 23:03 · Modified 22/05/2025 09:51

Export JSON

Essential information

Published
21/05/2025 23:03
Modified
22/05/2025 09:51
Tags
2025-05-21 cloud container security cryptocurrency mining dero docker golang malware linux nginx persistence port scanning
Related entities
3 observables, 7 techniques (mitre), 1 malware

Description

A new mining campaign is infecting containerized environments through exposed APIs. The attack uses two components: '' for propagation and '' for mining. The '' malware scans for vulnerable hosts, creates malicious containers, and compromises existing ones. It maintains and spreads without a command-and-control server. The '' component is a modified DeroHE CLI miner with hardcoded wallet and node addresses. This campaign demonstrates the potential risks of insecurely published APIs and the need for robust measures.

External references