Cetus is a Linux-focused Docker cryptojacking worm attributed to TeamTNT that targets unsecured Docker daemons exposed for remote administration. Its primary purpose is to deploy a Monero miner and propagate to additional Docker hosts. The malware was observed abusing the Docker API through the Docker command-line interface, launching containers on victim systems, installing required tooling, and copying its components into the container environment. It disguises itself as legitimate Docker-related software, including impersonation of Portainer, and deploys an obfuscated XMRig miner under benign-looking naming to reduce suspicion.
Operationally, Cetus combines mining and worm-like propagation. It scans both local and external networks for reachable Docker services, using Masscan to probe random subnets for exposed daemons. After identifying a target, it verifies exploitability by starting a container on the remote host, installs dependencies, places its malicious binaries, and modifies shell startup behavior to trigger execution after restart or interactive root shell access. Its core functionality includes separate routines for starting the miner and for scanning and infecting additional systems.
Cetus is associated with TeamTNT based on infrastructure and monetization overlap with earlier TeamTNT cloud and container cryptojacking activity. The malware fits the group’s broader pattern of targeting Linux servers, cloud workloads, and containerized environments for illicit cryptocurrency mining. High-confidence reporting ties Cetus specifically to attacks against exposed Docker environments rather than general-purpose desktop systems. Its behavior reflects increasing sophistication in container-focused cryptojacking, including propagation, persistence within compromised container contexts, and defense-evasion through masquerading and miner obfuscation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog will detail the discovery of Cetus, a new and improved Docker cryptojacking worm mining for Monero that was found in a Docker daemon honeypot we created.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
XMRig miner is one of the most widely used cryptominers for cryptojacking attacks... in order to deceive them in this attack, it was fully obfuscated, which made the reverse engineering process harder.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom TeamTNT malware for Docker environments that launches a miner and propagates to other exposed Docker servers.
Referenced as a prior example of Monero-focused cryptojacking activity.
Mentioned only as related background content; described as a cryptojacking worm targeting Docker daemons, but not part of the main event.
Cetus is a Docker-targeting cryptojacking worm that scans for unsecured Docker daemons on port 2375, spreads via the Docker REST API using the Docker CLI, copies itself as a fake Portainer binary, deploys an obfuscated XMRig miner disguised as docker-cache, and mines Monero using victim CPU resources.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.