• Latest
  • Trending
LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave

LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave

April 22, 2022
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Embracing the crypto evolution: Institutional adaptation and the … – Arabian Business

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Acala Spikes 5% on Binance's New Altcoin Pairs News — Can ACA … – CCN.com

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Bitcoin Spark, BNB, and Toncoin: Price Outlook in Upcoming Bull Run – CryptoPotato

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Crypto Price Today: Bitcoin holds $34,000; Ethereum slips below $1,800; most altcoins up – Business Today

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

The Next Bull Market Is Approaching: Sparking Opportunities For … – CryptoPotato

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Crypto Analyst Benjamin Cowen Says Fed Pivot and Altcoin Rallies Won’t Happen Until This Occurs – The Daily Hodl

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Litecoin Pronóstico del Precio: LTC insinúa una corrección del 15% si se cumplen estas condiciones clave – FXStreet

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Brazil's USDT adoption soars in 2023, makes up 80% of all crypto transactions – Cointelegraph

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Can Presales Like Scorpion Casino Token Match the Historic … – NewsWatch

October 29, 2023
Saturday, May 17, 2025
EGROW ONLINE
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoins
  • ADA
  • Litecoin
  • Dogecoin
  • ICO
  • Ripple
  • Market & Analysis
  • Videos
No Result
View All Result
EGROW ONLINE
No Result
View All Result

LemonDuck botnet plunders Docker cloud instances in cryptocurrency crime wave

by admin
April 22, 2022
in Cryptocurrency
0


Charlie Osborne

Operators of the LemonDuck botnet are targeting Docker instances in a cryptocurrency mining campaign.

LemonDuck is cryptocurrency mining malware wrapped up in a botnet structure. The malware exploits older vulnerabilities to infiltrate cloud systems and servers, including the Microsoft Exchange ProxyLogon bugs, EternalBlue, and BlueKeep.

As noted by Microsoft’s security team in 2021, the threat actors behind the malware are known to be selective when it comes to timing and may trigger an attack when teams are focused on “patching a popular vulnerability rather than investigating compromise.”

LemonDuck has expanded its operations from Windows machines also to include Linux and Docker. In an ongoing, active campaign, Crowdstrike says that Docker APIs are being targeted to obtain initial access to cloud instances.

Docker is used for running containers in the cloud. On Thursday, the cybersecurity researchers said that LemonDuck will take advantage of misconfigurations in instances that cause API exposure to deploy exploit kits and load malware.

In a case observed by the team, an exposed API was abused to run a custom Docker ENTRYPOINT instruction and download “core.png,” an image file disguised as a Bash script.

The file was downloaded from a domain in LemonDuck’s “vast” command-and-control (C2) infrastructure.

“CrowdStrike found multiple campaigns being operated via the domain targeting Windows and Linux platforms simultaneously,” the researchers noted.

Core.png will launch a Linux cronjob inside the vulnerable container and then download a secondary Bash file, “a.asp,” the main LemonDuck payload.

The cronjob will trigger LemonDuck. The malware will first kill several processes, including network connections, rival cryptocurrency mining operations, and existing ties to mining pools. LemonDuck will also target known daemons tasked with monitoring, such as Alibaba Cloud’s monitoring service.

Now the server has been prepared, a cryptocurrency mining operation begins. XMRig, used to generate Monero (XMR), is launched with a configuration set to proxy pools — an attempt to hide the true cryptocurrency wallet address of the attacker.

LemonDuck doesn’t stop at just one Docker instance, however. The malware will also search for SSH keys in the file system to log into other servers and repeat its malicious operations.

“Due to the cryptocurrency boom in recent years, combined with cloud and container adoption in enterprises, cryptomining is proven to be a monetarily attractive option for attackers, the researchers say. “Since cloud and container ecosystems heavily use Linux, it drew the attention of the operators of botnets like LemonDuck, which started targeting Docker for cryptomining on the Linux platform.”

Previous and related coverage


Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0




Source link

YOU MAY ALSO LIKE

Brazil's USDT adoption soars in 2023, makes up 80% of all crypto transactions – Cointelegraph

Cryptocurrency and Terrorism: Wall Street Journal Corrects Funding … – TOKENPOST

Tags: BotnetcloudcrimeCryptocurrencyDockerinstancesLemonDuckplunderswave
ShareTweetPin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result

Recent News

Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023

Recent News

Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023

Categories

  • ADA
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • ICO
  • Litecoin
  • Market & Analysis
  • Ripple
  • Videos

Follow Us

Find Via Tags

Ada Altcoin altcoins analysis Analyst Analytics Big Binance Bitcoin Blockchain BNB BTC Buy Cardano Coin Cointelegraph Crypto cryptocurrencies Cryptocurrency Digital DOGE Dogecoin ETH Ethereum finance Heres Insight Inu investors Litecoin LTC market Network news Prediction price Ripple SEC Shiba Solana Today Token Top week XRP
  • privacy And Policy
  • About Us

© 2020 Egrow Online

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoins
  • ADA
  • Litecoin
  • Dogecoin
  • ICO
  • Ripple
  • Market & Analysis
  • Videos

© 2020 Egrow Online