A newly discovered Linux malware campaign is compromising unsecured Docker infrastructure worldwide, turning exposed servers into part of a decentralized cryptojacking network that mines the privacy coin Dero DERO.
According to a report by cybersecurity firm Kaspersky, the attack begins by exploiting publicly exposed Docker APIs over port 2375. Once access is gained, the malware spawns malicious containers. It infects already-running ones, siphoning system resources to mine Dero and scan for additional targets without requiring a central command server.
In software terms, a docker is a set of applications or platform tool and products that use OS-level virtualization to deliver software in small packages called containers.
The threat actor behind the operation deployed two Golang-based implants: one named “nginx” (a deliberate attempt to masquerade as the legitimate web server software), and another called “cloud,” which is the actual mining software used to generate Dero.
We współpracy z: https://www.coindesk.com/tech/2025/05/28/privacy-crypto-dero-targeted-with-new-self-spreading-malware