29 Nov Vulnerable Docker instances targeted in cryptocurrency mining campaign
[ad_1]
Unknown hackers have launched a new campaign that’s actively scanning for vulnerable Docker application container instances to inject cryptomining code.
Discovered by cybersecurity firm Bad Packets LLC, the group is actively scanning for vulnerable Docker instances that have application programming interface endpoints exposed to the internet.
Although efforts by hackers to find and hijack servers are common, this case is specifically notable because of the volume: Those behind it are scanning more than 59,000 IP networks in an attempt to identify vulnerable instances.
“What set this campaign apart was the large uptick of scanning activity,” Troy Mursch, chief research officer and co-founder of Bad Packets, told ZDNet Tuesday. “This alone warranted further investigation to find out what this botnet was up to. This isn’t your average script kiddie exploit attempt. There was a moderate level of effort put into this campaign, and we haven’t fully analyzed every…
[ad_2]
Source link