Site icon WinCert

New botnet exploits Docker containers

<p>According to researchers from CrowdStrike&comma; a new botnet was discovered that uses exposed Docker APIs to compromise devices like Microsoft Exchanges servers&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4599" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2022&sol;04&sol;stock-trading-ga1d0059a7&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"427" &sol;><&sol;p>&NewLine;<p>It appears that an unknown threat actor is using the LemonDuck crypto mining botnet which targets Exchange servers via ProxyLogon in order to mine cryptocurrency&period;<&sol;p>&NewLine;<p>After looking for exposed Docker APIs for unauthorized access&comma; the attacker can run a malicious container by using a custom entry point to download the Bash script disguised as a core&period;png image file&period;<&sol;p>&NewLine;<p>After gaining initial access to server resources&comma; the attacker can use known exploits to escalate privileges and install crypto miners while spreading across the network&period; They can also install files that prevent detection from any antivirus scanning applications that are installed on compromised machines&period;<&sol;p>&NewLine;<p>The attackers are using XMRig to mine Monero which is a privacy-oriented cryptocurrency that claims to be very difficult to trace&period;<&sol;p>&NewLine;<p>Security researchers from CrowdStrike also said that LemonDuck comes with a file called &&num;8220&semi;a&period;asp&&num;8221&semi; which can actually disable the aliyun service on Alibaba&&num;8217&semi;s Cloud and therefore avoid being detected&period;<&sol;p>&NewLine;<p>With the rising price of cryptocurrencies in the past few years&comma; crypto miners have become extremely popular&comma; especially since they can be easily sold on many crypto markets&period;<&sol;p>&NewLine;

Exit mobile version