Sophisticated Cyberattack Campaign Targets Containerized Environments to Deploy Dero Cryptocurrency Miner

Kaspersky Security Services experts have discovered a complex cyberattack campaign targeting organizations that expose Docker APIs without robust security controls. The attackers inject two types of malware into compromised systems: a miner for the Dero cryptocurrency and a propagation malware that can spread the campaign to other insecure container networks. According to expert estimates, any organization operating containerized infrastructure with exposed Docker APIs can be a potential target, including technology companies, software development firms, hosting providers, cloud service providers, and more.

Key Takeaways:

  • The campaign targets organizations that expose Docker APIs without robust security controls, potentially including technology companies, software development firms, hosting providers, cloud service providers, and more.
  • In 2025, there are approximately 500 occurrences of insecurely published Docker API default ports worldwide each month, providing potential entry points for attackers.
  • The attackers inject two types of malware into compromised systems: a Dero cryptocurrency miner and a propagation malware that can spread the campaign to other insecure container networks.
  • The malware maintains persistence, ensures execution of the miner, and scans for other exposed environments, allowing attackers to operate without traditional Command-and-Control (C2) servers.
  • Each infected container acts as a new source of attack, potentially leading to exponential growth of infections if security measures are not implemented in the targeted networks.
  • The attackers embedded the names 'nginx' and 'cloud' directly in the binary, utilizing a classic masquerading tactic to deceive analysts and automated defenses.

Statistics:

  • There are approximately 485 published Docker API default ports worldwide each month on average, according to Shodan (2025).
  • The campaign has the potential to target any organization operating containerized infrastructure with exposed Docker APIs.
  • The malware injects into compromised systems, creating a propagation malware that spreads the campaign to other insecure container networks.

Sources:

[1] Kaspersky Security Services experts, through a compromise assessment project.

[2] Shodan, 2025, cited in Kaspersky report (exact reference not provided).

[3] Kaspersky Security Services experts, in an incident response and compromise assessment capacity.

[4] Kaspersky experts, in a report detailing the campaign and its potential attack surface.