Attackers have been abusing improperly exposed Docker daemon APIs, especially unauthenticated services on port 2375, to take control of running containers and deploy malware. One documented campaign used the Dofloo (AESDDoS) Trojan to enumerate containers and run malicious payloads with Docker commands, giving operators DDoS capability, host profiling data, and a foothold for follow-on activity such as cryptojacking or broader system compromise.
Public tooling has also lowered the barrier to exploiting these weaknesses. The BOtB container assessment tool demonstrates how exposed Docker daemons, privileged container configurations, Kubernetes service account exposure, metadata service access, Linux kernel keyring leakage, and even runc escape flaw CVE-2019-5736 can be used to break out of containers or extract secrets in CI/CD and live environments. Docker’s guidance recommends protecting the daemon socket and restricting remote API access to trusted systems, underscoring that exposed or misconfigured container management interfaces can quickly turn a single container issue into host-level compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository documents BOtB (Break Out The Box), a CLI tool for container analysis and exploitation that includes checks and exploitation paths for exposed Docker daemons, privileged containers, Kubernetes secrets, metadata services, keyrings, and CVE-2019-5736.
A previous campaign in late April used a critical Atlassian Confluence Server and Data Center server-side template injection vulnerability to deploy Dofloo on Linux and Windows servers.
In March, Imperva detected a campaign that abused exposed Docker APIs while exploiting CVE-2019-5736 in runc to gain root-level code execution on hosts.
Juniper Networks researchers observed attacks against misconfigured Docker services in which attackers added their own containers to run Monero mining scripts.
Researchers also observed a separate campaign in October 2018 that scanned for exposed Docker hosts and deployed coin-mining malware.
The article states that campaigns scanning for exposed Docker services and deploying cryptocurrency miners were already active in March 2018.
Misconfigured Docker services had been under sustained attack since early 2018, according to the reporting cited in the article.
The Dofloo malware family, also known as AESDDoS, was first detected in 2014 and later became associated with large-scale botnet activity.
Trend Micro observed attackers scanning TCP port 2375 for exposed Docker APIs, enumerating running containers, and using docker exec to deploy a Dofloo Trojan variant for DDoS and follow-on compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
docs.docker.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.