|

Illicit Bitcoin mining malware detected by researchers

  • Researchers at Aqua Security have detected a campaign that targets thousands of Docker servers with a BTC miner.
  • The scope and ambition of the campaign reveal that the attackers have been using significant infrastructure and resources.

Cybersecurity researchers at Aqua Security have identified a campaign that targets thousands of Docker servers daily with a Bitcoin (BTC) miner. In a recent report published by them, the firm issued a warning regarding the attack, which has “been going on for months, with thousands of attempts taking place nearly on a daily basis.”

The warning reads:

These are the highest numbers we’ve seen in some time, far exceeding what we have witnessed to date.

The scope and ambition reveal that the fraudulent Bitcoin mining campaign is not just “an improvised endeavor” as the people behind it must be relying on major infrastructure and resources.

Aqua Security has spotted the malware as a Golang-based Linux agent, known as Kinsing. The malware propagates by exploiting misconfigurations in Docker API ports. It runs an Ubuntu container, which downloads Kinsing and then tries to spread the malware to further hosts and containers. According to the researchers, the campaign’s goal is to deploy a crypto miner on the compromised host. This was planned to achieve by first exploiting the open port and then carrying through with a series of evasion tactics.

The team at Aqua Security has been able to provide valuable, detailed insight into the aspects of the malware campaign. They claim it to be a “growing threat to cloud-native environments.” The researchers noted that the attackers have been stepping up their game to carry out sophisticated and ambitious attacks. To fight this, enterprise security teams need to build a robust strategy to mitigate new risks. 

Aqua recommends security teams to locate all cloud resources and classify them in a logical structure, review their authorization and authentication policies, and adjust basic security policies based on the principle of “least privilege.” Teams are also advised to investigate logs to identify user actions that register as anomalies and implement cloud security tools to strengthen their strategy.

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Ripple bulls defend key support amid waning retail demand and ETF inflows

XRP ticks up above $1.40 support, but waning retail demand suggests caution. XRP attracts $4 million in spot ETF inflows on Thursday, signaling renewed institutional investor interest.

Crypto Today: Bitcoin, Ethereum, XRP rebound as risk appetite improves

Bitcoin rises marginally, nearing the immediate resistance of $68,000 at the time of writing on Friday. Major altcoins, including Ethereum and Ripple, hold key support levels as bulls aim to maintain marginal intraday gains.

Bitcoin Weekly Forecast: No recovery in sight 

Bitcoin price continues to trade sideways between $65,729 and $71,746, extending its consolidation since February 7. US-spot ETFs record an outflow of $403.90 million through Thursday, pointing to the fifth consecutive week of withdrawals.

Pi Network Price Forecast: PI recovery stalls amid profit-taking

Pi Network tests 50-day EMA support on Friday, after a 5% decline the previous day. PiScan data shows large deposits on CEXs totaling over 4 million PI tokens in the last 24 hours, reflecting an exodus of investors taking profits.

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: No recovery in sight

Bitcoin (BTC) price continues to trade within a range-bound zone, hovering around $67,000 at the time of writing on Friday, and falling slightly so far this week, with no signs of recovery.