Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Hyperliquid hits new ATH – What could stop HYPE from reaching $100?

June 1, 2026

Bitcoin Mining Difficulty Edges Higher, Climbing 1.72% to 138.96 Terahashes

June 1, 2026

“Today Is a Historic Day for the Cryptocurrency Market”

June 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Crypto-Mining Botnet Goes After Misconfigured Docker APIs
Crypto-Mining Botnet Goes After Misconfigured Docker APIs
Security and Privacy

Crypto-Mining Botnet Goes After Misconfigured Docker APIs

June 23, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A notorious cryptocurrency mining botnet has begun targeting misconfigured Docker APIs, according to CrowdStrike.

LemonDuck has been observed exploiting ProxyLogon vulnerabilities in Microsoft Exchange Server and using EternalBlue and other exploits to mine cryptocurrency, escalate privileges and move laterally inside compromised networks.

Now its attention has turned to one of the world’s most popular containerization platforms.

The botnet is targeting exposed Docker APIs in order to gain initial access, CrowdStrike explained.

“It runs a malicious container on an exposed Docker API by using a custom Docker Entrypoint to download a ‘core.png’ image file that is disguised as Bash script,” it said in a blog post yesterday.

Before the payload – an “a.asp” file – is downloaded and mining can begin, it performs several actions, including killing the processes, IOC file paths and C&C connections of competing crypto-mining groups.

The a.asp file also has the capability to switch off Alibaba’s cloud monitoring service in order to fly under the radar of network defenders.

LemonDuck attempts to move laterally by searching for SSH keys on a filesystem, using them to log into additional servers and run its malicious scripts.

The researchers also found multiple campaigns running from many of the C&C servers associated with LemonDuck, including ones targeting Windows and Linux machines.

“Due to the cryptocurrency boom in recent years, combined with cloud and container adoption in enterprises, cryptomining is proven to be a monetarily attractive option for attackers,” CrowdStrike concluded.

“Since cloud and container ecosystems heavily use Linux, it drew the attention of the operators of botnets like LemonDuck, which started targeting Docker for cryptomining on the Linux platform.”

See also  Crypto-Mining Malware Tops Charts, Targets Apps

The campaign highlights the need for administrators to ensure their container environments are correctly configured according to industry best practices, and ideally with cloud workload security and detection and response tools installed.

Source link

APIs Botnet Cryptomining Docker Misconfigured
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026

PureLogs Variant Steals Data via Purchase Order Lures

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

If AI Image Generators Are So Smart, Why Do They Struggle to Write and Count?

July 29, 2023

Agnostic Nature of Blockchain Technology ‘Makes It the Ideal Foundation for Global Travel Industry’ — Pablo Castillo

October 17, 2023

Crypto Tanked (But We’re Still Bullish…Here’s Why)

April 3, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Hyperliquid hits new ATH – What could stop HYPE from reaching $100?

June 1, 2026

Bitcoin Mining Difficulty Edges Higher, Climbing 1.72% to 138.96 Terahashes

June 1, 2026

“Today Is a Historic Day for the Cryptocurrency Market”

June 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$71,997.00-2.48%
  • ethereumEthereum(ETH)$1,975.60-2.23%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$690.42-4.63%
  • rippleXRP(XRP)$1.30-2.98%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$80.49-2.51%
  • tronTRON(TRX)$0.3497380.49%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • HyperliquidHyperliquid(HYPE)$73.037.70%