Uncovering a Tor-Enabled Docker Exploit
Essential information
- Published
- 18/06/2025 10:52
- Modified
- 18/06/2025 11:27
- Tags
- 2025-06-18 api abuse container exploitation cryptocurrency mining docker ssh backdoor tor xmrig zstandard compression
- Related entities
- 1 vulnerabilities (cve), 6 observables, 5 techniques (mitre), 1 malware, 3 others
Description
A sophisticated attack campaign exploits exposed Docker Remote APIs and leverages the Tor network to deploy stealthy cryptocurrency miners. The attackers gain access to containerized environments, use Tor to mask their activities, and employ the ZStandard compression algorithm for efficient payload delivery. The attack sequence involves initial access through the Docker API, container creation with host system access, deployment of a malicious script, SSH configuration modification for persistent access, installation of supporting tools, and finally the execution of an XMRig crypto miner. This campaign particularly targets cloud-heavy sectors like technology, finance, and healthcare. The attackers demonstrate advanced evasion techniques and utilize various MITRE ATT&CK framework tactics.