Threat actors were observed targeting exposed Docker APIs by deploying a malicious container image named gin with the --privileged option, then abusing the Linux cgroups release_agent mechanism to escape the container and execute code on the host. Trend Micro detected the activity in a honeypot after the environment was identified by the zgrab scanner, showing how internet-exposed container management interfaces can be rapidly discovered and exploited.
The attack chain used a script called calm.sh, which dropped another script named cmd and launched a fake nginx binary that was actually an ELF cryptocurrency miner. If the container escape attempt failed, the attackers still tried to mine cryptocurrency directly on the vulnerable server, underscoring that misconfigured privileged containers can turn a Docker deployment into a host-level compromise and that image security requires more than basic vulnerability scanning alone.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In October 2021, Trend Micro observed attackers abusing exposed Docker REST APIs to deploy malicious containers that scanned for more exposed Docker services, escaped to hosts, installed Monero miners, and added TeamTNT SSH access. Trend Micro linked the activity to TeamTNT through infrastructure, tooling, SSH key usage, and Docker Hub accounts such as 'alpineos,' and said Docker removed the identified malicious accounts.
Felix Wilhelm of Google's Security Team published a proof of concept showing how a privileged Docker container or Kubernetes pod could escape to the host by abusing the cgroups release_agent feature. This technique later matched the method used in the observed attack.
Trend Micro observed an attack against its honeypot after an exposed Docker API was discovered by the zgrab scanner. The attacker pulled a malicious container image named "gin," ran it with the privileged option enabled, and used scripts including calm.sh to attempt host escape and deploy a disguised cryptocurrency miner.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.