Threat actors abused exposed Docker servers by creating a malicious Alpine Linux container that launched a multi-stage infection chain, ultimately installing both a cryptocurrency miner and an IRC-based DDoS bot. The attack used a Bash script named XMI and a Python script named d.py to download payloads, establish persistence, and spread further, with the miner identified as Coinminer.Linux.MALXMR.UWELD and the bot as a Kaiten/Tsunami variant detected as Backdoor.Linux.KAITEN.AMV.
The malware relied on Base64 obfuscation, cron jobs, and a service placed in /etc/init.d for persistence, and it attempted lateral movement by harvesting targets from /.ssh/known_hosts; researchers also found commented-out SSH brute-force propagation code. Trend Micro said the miner wallet overlapped with earlier campaigns exploiting CVE-2019-3396 and CVE-2017-5638, previously associated in public reporting with the 8220 mining group, while the DDoS component communicated with command-and-control infrastructure including c4k[.]xpl[.]pwndns[.]pw, 104[.]244[.]75[.]25, and 107[.]189[.]11[.]170.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The report states that an earlier Docker-focused attack had been reported in May and likewise used a malicious Alpine Linux container to host both a cryptocurrency miner and a DDoS bot.
Trend Micro reported an attack in which threat actors connected to exposed Docker servers, created a malicious Alpine Linux container, and deployed both a coinminer and an IRC-based Kaiten/Tsunami DDoS bot. The infection chain used XMI and d.py scripts for persistence, lateral movement, and payload delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.