Researchers identified a large cryptojacking operation that abused public container registries by uploading 30 malicious images across 10 Docker Hub accounts, which collectively recorded more than 20 million pulls. The images were designed to deploy cryptocurrency miners on victim systems, with most samples mining Monero and frequently using the open-source miner XMRig.
The campaign was tied to multiple Docker Hub accounts, including azurenql, 021982, dockerxmrig, ggcloud1, and ggcloud2, which researchers assessed as part of the same broader operation. Attackers used multiple image tags to support different CPU architectures, operating systems, and miner variants, increasing compatibility and reach, and the observed mining activity was estimated to have generated roughly $200,000 in cryptocurrency while indicating a wider malicious-image problem across public registries.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Unit 42 reported finding 30 malicious container images across 10 Docker Hub accounts that were being used for cryptojacking. The images had accumulated more than 20 million pulls, and the researchers linked several accounts to a broader Monero-mining campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.