news4global
  • Home
  • Bitcoin
  • Blockchain
  • Business
  • Latest news
  • Market
  • Regulation
  • VideosHot
    FTM Fantom Crypto Price News Today – Elliott Wave Technical Analysis Update and Price Now!

    FTM Fantom Crypto Price News Today – Elliott Wave Technical Analysis Update and Price Now!

    BREAKING: COINBASE AND BLACKROCK ARE SENDING PEPE COIN TO $0.01 – EXPLAINED – PEPE COIN NEWS TODAY

    BREAKING: COINBASE AND BLACKROCK ARE SENDING PEPE COIN TO $0.01 – EXPLAINED – PEPE COIN NEWS TODAY

    Polkadot DOT Price News Today – Technical Analysis Update Now, Price Now! Elliott Wave Analysis!

    Polkadot DOT Price News Today – Technical Analysis Update Now, Price Now! Elliott Wave Analysis!

    The Market On The Edge: Gareth Soloway's Shocking Revelation

    The Market On The Edge: Gareth Soloway's Shocking Revelation

    What Is a Trading Strategy || Guide to Cryptocurrency Trading Strategy for Beginners

    What Is a Trading Strategy || Guide to Cryptocurrency Trading Strategy for Beginners

    Polygon MATIC Price News Today – Elliott Wave Technical Analysis Update, This is Happening Now!

    Polygon MATIC Price News Today – Elliott Wave Technical Analysis Update, This is Happening Now!

    Injective Protocol INJ Coin Price News Today – Elliott Wave Technical Analysis and Price Prediction!

    Injective Protocol INJ Coin Price News Today – Elliott Wave Technical Analysis and Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

No Result
View All Result
  • Home
  • Bitcoin
  • Blockchain
  • Business
  • Latest news
  • Market
  • Regulation
  • VideosHot
    FTM Fantom Crypto Price News Today – Elliott Wave Technical Analysis Update and Price Now!

    FTM Fantom Crypto Price News Today – Elliott Wave Technical Analysis Update and Price Now!

    BREAKING: COINBASE AND BLACKROCK ARE SENDING PEPE COIN TO $0.01 – EXPLAINED – PEPE COIN NEWS TODAY

    BREAKING: COINBASE AND BLACKROCK ARE SENDING PEPE COIN TO $0.01 – EXPLAINED – PEPE COIN NEWS TODAY

    Polkadot DOT Price News Today – Technical Analysis Update Now, Price Now! Elliott Wave Analysis!

    Polkadot DOT Price News Today – Technical Analysis Update Now, Price Now! Elliott Wave Analysis!

    The Market On The Edge: Gareth Soloway's Shocking Revelation

    The Market On The Edge: Gareth Soloway's Shocking Revelation

    What Is a Trading Strategy || Guide to Cryptocurrency Trading Strategy for Beginners

    What Is a Trading Strategy || Guide to Cryptocurrency Trading Strategy for Beginners

    Polygon MATIC Price News Today – Elliott Wave Technical Analysis Update, This is Happening Now!

    Polygon MATIC Price News Today – Elliott Wave Technical Analysis Update, This is Happening Now!

    Injective Protocol INJ Coin Price News Today – Elliott Wave Technical Analysis and Price Prediction!

    Injective Protocol INJ Coin Price News Today – Elliott Wave Technical Analysis and Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

    Cardano ADA Price News Today – Elliott Wave Technical Analysis and Price Now! Price Prediction!

No Result
View All Result
news4global
No Result
View All Result
Home Bitcoin

LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave

April 22, 2022
Reading Time: 2 mins read
0
LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

U.S. congressman says crypto mining tax scrapped in debt ceiling deal – Forkast News

May 30, 2023
Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

Hong Kong Web3 industry forms new associations – Forkast News

May 29, 2023

Operators of the LemonDuck botnet are targeting Docker instances in a cryptocurrency mining campaign.

LemonDuck is cryptocurrency mining malware wrapped up in a botnet structure. The malware exploits older vulnerabilities to infiltrate cloud systems and servers, including the Microsoft Exchange ProxyLogon bugs, EternalBlue, and BlueKeep.

As noted by Microsoft’s security team in 2021, the threat actors behind the malware are known to be selective when it comes to timing and may trigger an attack when teams are focused on “patching a popular vulnerability rather than investigating compromise.”

LemonDuck has expanded its operations from Windows machines also to include Linux and Docker. In an ongoing, active campaign, Crowdstrike says that Docker APIs are being targeted to obtain initial access to cloud instances.

Docker is used for running containers in the cloud. On Thursday, the cybersecurity researchers said that LemonDuck will take advantage of misconfigurations in instances that cause API exposure to deploying exploit kits and load malware.

In a case observed by the team, an exposed API was abused to run a custom Docker ENTRYPOINT instruction and download “core.png,” an image file disguised as a Bash script.

The file was downloaded from a domain in LemonDuck’s “vast” command-and-control (C2) infrastructure.

“CrowdStrike found multiple campaigns being operated via the domain targeting Windows and Linux platforms simultaneously,” the researchers noted.

Core.png will launch a Linux cronjob inside the vulnerable container and then download a secondary Bash file, “a.asp,” the main LemonDuck payload.

The cronjob will trigger LemonDuck. The malware will first kill several processes, including network connections, rival cryptocurrency mining operations, and existing ties to mining pools. LemonDuck will also target known daemons tasked with monitoring, such as Alibaba Cloud’s monitoring service.

Now the server has been prepared, a cryptocurrency mining operation begins. XMRig used to generate Monero (XMR), is launched with a configuration set to proxy pools — an attempt to hide the true cryptocurrency wallet address of the attacker.

LemonDuck doesn’t stop at just one Docker instance, however. The malware will also search for SSH keys in the file system to log into other servers and repeat its malicious operations.

“Due to the cryptocurrency boom in recent years, combined with cloud and container adoption in enterprises, cryptomining is proven to be a monetarily attractive option for attackers, the researchers say. “Since cloud and container ecosystems heavily use Linux, it drew the attention of the operators of botnets like LemonDuck, which started targeting Docker for cryptomining on the Linux platform.”

See also


Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0


Share76Tweet47

Related Posts

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

U.S. congressman says crypto mining tax scrapped in debt ceiling deal – Forkast News

by admin
May 30, 2023
0

U.S. congressman says crypto mining tax scrapped in debt ceiling deal  Forkast News

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

Hong Kong Web3 industry forms new associations – Forkast News

by admin
May 29, 2023
0

Hong Kong Web3 industry forms new associations  Forkast News

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

Bipartisan Agreement on US Debt Ceiling Sends Bitcoin Above $28 … – Securities.io

by admin
May 29, 2023
0

Bipartisan Agreement on US Debt Ceiling Sends Bitcoin Above $28 ...  Securities.io

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

Americans Say There's Still One Brand Worse Than FTX – Blockworks

by admin
May 28, 2023
0

Americans Say There's Still One Brand Worse Than FTX  Blockworks

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs – Cointelegraph

Shaquille O’Neal And Other Celebrities Are Facing A Lawsuit Due To Their Role In Promoting Cryptocurrency – Yahoo News

by admin
May 27, 2023
0

Shaquille O’Neal And Other Celebrities Are Facing A Lawsuit Due To Their Role In Promoting Cryptocurrency  Yahoo News

Load More
  • Trending
  • Comments
  • Latest

Bitcoin Is ‘Definitely Not a Fraud,’ CEO of Mobile-Only Bank Revolut Says

March 2, 2022

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

March 3, 2022
How online shopping has changed over the last 30 years | National

How online shopping has changed over the last 30 years | National

April 6, 2022
Protocon Announces ‘Contract Model’, an Alternative

Protocon Announces ‘Contract Model’, an Alternative

April 6, 2022

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Poly Blackwire 5220 USB-A Wired Headset (Plantronics) – Flexible Noise-Canceling Boom Mic – Ergonomic Design – Connect to PC/Mac, Mobile via USB-A or 3.5 mm – Works w/Teams, Zoom – Amazon Exclusive

Poly Blackwire 5220 USB-A Wired Headset (Plantronics) – Flexible Noise-Canceling Boom Mic – Ergonomic Design – Connect to PC/Mac, Mobile via USB-A or 3.5 mm – Works w/Teams, Zoom – Amazon Exclusive

May 30, 2023
HyperX Cloud Stinger – Gaming Headset, Lightweight, Comfortable Memory Foam, Swivel to Mute Noise-Cancellation Mic, Works on PC, PS4, PS5, Xbox One, Xbox Series X|S and Mobile,Black

HyperX Cloud Stinger – Gaming Headset, Lightweight, Comfortable Memory Foam, Swivel to Mute Noise-Cancellation Mic, Works on PC, PS4, PS5, Xbox One, Xbox Series X|S and Mobile,Black

May 30, 2023
CASCHO Wireless Earbuds Bluetooth Headphones 60Hrs Playtime HD Stereo Audio Digital LED Display Over-Ear Earphones with Earhook Waterproof Headset with Mic for Sport Running Workout

CASCHO Wireless Earbuds Bluetooth Headphones 60Hrs Playtime HD Stereo Audio Digital LED Display Over-Ear Earphones with Earhook Waterproof Headset with Mic for Sport Running Workout

May 30, 2023
India's protesting wrestlers to sink medals in Ganges

India's protesting wrestlers to sink medals in Ganges

May 30, 2023

Latest News

Poly Blackwire 5220 USB-A Wired Headset (Plantronics) – Flexible Noise-Canceling Boom Mic – Ergonomic Design – Connect to PC/Mac, Mobile via USB-A or 3.5 mm – Works w/Teams, Zoom – Amazon Exclusive

Poly Blackwire 5220 USB-A Wired Headset (Plantronics) – Flexible Noise-Canceling Boom Mic – Ergonomic Design – Connect to PC/Mac, Mobile via USB-A or 3.5 mm – Works w/Teams, Zoom – Amazon Exclusive

May 30, 2023
HyperX Cloud Stinger – Gaming Headset, Lightweight, Comfortable Memory Foam, Swivel to Mute Noise-Cancellation Mic, Works on PC, PS4, PS5, Xbox One, Xbox Series X|S and Mobile,Black

HyperX Cloud Stinger – Gaming Headset, Lightweight, Comfortable Memory Foam, Swivel to Mute Noise-Cancellation Mic, Works on PC, PS4, PS5, Xbox One, Xbox Series X|S and Mobile,Black

May 30, 2023

Categories

Site Navigation

  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms and services
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms and services

© 2022 Designed by news4global

No Result
View All Result
  • Home
  • Bitcoin
  • Blockchain
  • Business
  • Latest news
  • Market
  • Regulation
  • Videos

© 2022 Designed by news4global