Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cybercriminals are using Docker API servers for SRBMiner cryptomining attacks
Global Security

Cybercriminals are using Docker API servers for SRBMiner cryptomining attacks

AdminBy AdminOctober 22, 2024No Comments2 Mins Read
Crypto Mining Attacks
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 22, 2024Ravi LakshmananDocker Security / Cloud Security

Attacks on crypto-mining

Bad actors have been observed targeting Docker remote API servers according to Trend Micro’s new findings, to deploy the SRBMiner cryptominer on hacked instances.

“In this attack, the actor used a threat gRPC the protocol is over h2c evade security solutions and run their cryptomining operations on a Docker host,” researchers Abdelrahman Esmail and Sunil Bharti said in a technical report published today.

“The attacker first checked the availability and version of the Docker API, then proceeds with gRPC/h2c update requests and gRPC methods to manipulate Docker functions.”

Cyber ​​security

It all starts with the attacker running a discovery process to check public Docker API hosts for HTTP/2 protocol updates, then sending a connection update request to the h2c protocol (eg HTTP/2 without TLS). encryption).

The adversary also proceeds to inspect gRPC methods, which are designed to perform various tasks related to managing and operating a Docker environment, including health checks, file synchronization, authentication, secret management, and SSH redirection.

After the server processes the connection update request, the gRPC request “/moby.buildkit.v1.Control/Solve” is sent to create a container and then use it to mine XRP cryptocurrency with the SRBMiner payload hosted on GitHub.

Attacks on crypto-mining

“The attacker in this case used the gRPC protocol over h2c, effectively bypassing multiple layers of security, to deploy the SRBMiner cryptominer on a Docker host and illegally mine XRP cryptocurrency,” the researchers said.

The disclosure comes as the cyber security firm also made the announcement is observed attackers use exposed remote Docker API servers to deploy perfect malware. The campaign involves inspecting such servers, then creating a Docker container with the image “ubuntu:mantic-20240405” and executing a Base64-encoded payload.

Cyber ​​security

The shell script, in addition to checking for and stopping duplicates of itself, creates a bash script that in turn contains another Base64-encoded payload responsible for loading a malicious binary masquerading as a PHP file (“avatar.php”), and delivers a payload called httpd by repeating a the report from Aqua earlier this month.

Users are encouraged to secure remote Docker API servers by implementing strict access controls and authentication mechanisms to prevent unauthorized access, monitoring for any unusual activity, and implementing container security best practices.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.