Doki is a Linux malware family associated with attacks on exposed containerized environments, particularly systems reachable through misconfigured or open Docker daemon APIs. It has been observed executed inside containers and is notable for using dynamic command-and-control discovery mechanisms rather than relying solely on static infrastructure. Doki generates command-and-control destinations through a domain generation approach tied to Dogecoin blockchain data and has also leveraged DynDNS-related infrastructure and the dogechain.info API to derive or resolve command-and-control addresses. For communications, it uses the embedTLS library and has employed Ngrok tunneling both for command and control and for data exfiltration.
The malware uses defense-evasion tradecraft to blend into Linux environments, including disguising a component as a Linux kernel module. Reported behavior includes discovery of the current process identifier and scripted collection of information from predefined remote systems, with the collected data uploaded through attacker-controlled tunneling infrastructure. Doki has been discussed alongside other notable Linux threats targeting servers and cloud-hosted workloads, reflecting the broader trend of malware operators abusing containers as both an intrusion vector and an execution environment. In container-focused intrusions, access obtained through exposed Docker services can provide elevated privileges that enable follow-on post-compromise activity and potential lateral movement within the victim environment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
“APT41 DUST used compromised Google Workspace accounts for command and control… Carbon can use Pastebin to receive C2 commands… CHIMNEYSWEEP… use Telegram channels… DropBook… exploiting… Simplenote, DropBox… Facebook… Nightdoor… OneDrive or Google Drive for command and control… Turla has used… Pastebin, Dropbox, and GitHub for C2 communications.”
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
APT41 has used DGAs to change their C2 servers monthly. Aria-body has the ability to use a DGA for C2 communications. Astaroth has used a DGA in C2 communications. Bazar can implement DGA using the current date as a seed variable.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as another Linux threat.
Malware that establishes C2 and exfiltrates data, including via Ngrok.
Malware that disguises itself as a Linux kernel module.
Backdoor malware that searches for the current process PID.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.