216.73.217.22

Uncovering a Tor-Enabled Docker Exploit

· Published 18/06/2025 10:52 · Modified 18/06/2025 11:27

Export JSON

Essential information

Published
18/06/2025 10:52
Modified
18/06/2025 11:27
Tags
2025-06-18 api abuse container exploitation cryptocurrency mining docker ssh backdoor tor xmrig zstandard compression
Related entities
1 vulnerabilities (cve), 6 observables, 5 techniques (mitre), 1 malware, 3 others

Description

A sophisticated attack campaign exploits exposed Remote APIs and leverages the network to deploy stealthy cryptocurrency miners. The attackers gain access to containerized environments, use to mask their activities, and employ the algorithm for efficient payload delivery. The attack sequence involves initial access through the API, container creation with host system access, deployment of a malicious script, SSH configuration modification for persistent access, installation of supporting tools, and finally the execution of an crypto miner. This campaign particularly targets cloud-heavy sectors like technology, finance, and healthcare. The attackers demonstrate advanced evasion techniques and utilize various MITRE ATT&CK framework tactics.

External references