Exposed Docker APIs Under Attack in ‘Commando Cat’ Cryptojacking Campaign

February 4, 2024 at 12:19PM A new cryptojacking campaign, Commando Cat, targets exposed Docker API endpoints with multiple payloads, including XMRig cryptocurrency miner. The sophisticated campaign utilizes Docker as an initial access vector, deploys benign containers, and runs various payloads. It also drops additional payloads from a command-and-control server, posing a multi-faceted threat. (Word count: … Read more

Cryptojackers steal AWS credentials from GitHub in 5 minutes

October 30, 2023 at 02:36PM Security researchers have discovered a long-running cryptojacking campaign called “EleKtra-Leak” that clones GitHub repositories and steals exposed AWS credentials. The criminals behind the campaign are able to steal AWS credentials within minutes of them being exposed. They launch multiple Amazon EC2 instances to mine Monero. The researchers identified 474 miners … Read more