• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
exposed docker apis under attack in 'commando cat' cryptojacking campaign

Exposed Docker APIs Under Attack in ‘Commando Cat’ Cryptojacking Campaign

You are here: Home / General Cyber Security News / Exposed Docker APIs Under Attack in ‘Commando Cat’ Cryptojacking Campaign
February 1, 2024

Exposed Docker API endpoints around the internet are less than assault from a sophisticated cryptojacking campaign identified as Commando Cat.

“The marketing campaign deploys a benign container produced employing the Commando venture,” Cado security scientists Nate Bill and Matt Muir explained in a new report released these days. “The attacker escapes this container and operates many payloads on the Docker host.”

The campaign is thought to have been active considering the fact that the get started of 2024, producing it the second this kind of campaign to be learned in as a lot of months. In mid-January, the cloud security agency also get rid of light-weight on another activity cluster that targets vulnerable Docker hosts to deploy XMRig cryptocurrency miner as properly as the 9Hits Viewer computer software.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Commando Cat employs Docker as an original accessibility vector to provide a assortment of interdependent payloads from an actor-controlled server that is responsible for registering persistence, backdooring the host, exfiltrating cloud assistance service provider (CSP) credentials, and launching the miner.

Cybersecurity

The foothold attained by breaching inclined Docker scenarios is subsequently abused to deploy a harmless container working with the Commando open-resource software and execute a malicious command that will allow it to escape the confines of the container via the chroot command.

It also operates a series of checks to decide if expert services named “sys-kernel-debugger,” “gsc,” “c3pool_miner,” and “dockercache” are energetic on the compromised program, and proceeds to the subsequent phase only if this phase passes.

“The function of the look at for sys-kernel-debugger is unclear – this support is not applied any where in the malware, nor is it portion of Linux,” the researchers mentioned. “It is probable that the service is portion of a different campaign that the attacker does not want to contend with.”

The succeeding phase entails dropping additional payloads from the command-and-management (C2) server, like a shell script backdoor (consumer.sh) that’s able of adding an SSH critical to the ~/.ssh/authorized_keys file and creating a rogue user named “video games” with an attacker-recognized password and together with it in the /and so on/sudoers file.

Cryptojacking Campaign

Also shipped in a identical method are a few much more shell scripts – tshd.sh, gsc.sh, aws.sh – which are developed to fall Very small SHell, an improvised model of netcat referred to as gs-netcat, and exfiltrate qualifications and setting variables, respectively.

“As a substitute of employing /tmp, [gsc.sh] also uses /dev/shm as an alternative, which acts as a short-term file retail outlet but memory backed alternatively,” the researchers mentioned. “It is doable that this is an evasion system, as it is considerably much more popular for malware to use /tmp.”

Cybersecurity

“This also results in the artifacts not touching the disk, producing forensics to some degree harder. This approach has been applied prior to in BPFdoor – a higher profile Linux marketing campaign.”

The attack culminates in the deployment of a different payload which is delivered immediately as a Foundation64-encoded script as opposed to currently being retrieved from the C2 server, which, in flip, drops the XMRig cryptocurrency miner but not before doing away with competing miner procedures from the contaminated machine.

The actual origins of the danger actor behind Commando Cat are presently unclear, while the shell scripts and the C2 IP handle have been noticed to overlap with these linked to cryptojacking teams like TeamTNT in the past, increasing the likelihood that it could be a copycat team.

“The malware features as a credential stealer, highly stealthy backdoor, and cryptocurrency miner all in just one,” the researchers claimed. “This will make it multipurpose and ready to extract as much worth from infected machines as probable.”

Uncovered this post interesting? Follow us on Twitter  and LinkedIn to study additional special content material we submit.


Some areas of this report are sourced from:
thehackernews.com

Previous Post: «u.s. feds shut down china linked "kv botnet" targeting soho routers U.S. Feds Shut Down China-Linked “KV-Botnet” Targeting SOHO Routers
Next Post: FritzFrog Returns with Log4Shell and PwnKit, Spreading Malware Inside Your Network fritzfrog returns with log4shell and pwnkit, spreading malware inside your»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.