financetom
Technology
financetom
/
Technology
/
Privacy Crypto Dero Targeted With New Self-Spreading Malware
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Privacy Crypto Dero Targeted With New Self-Spreading Malware
May 28, 2025 8:23 AM

A newly discovered Linux malware campaign is compromising unsecured Docker infrastructure worldwide, turning exposed servers into part of a decentralized cryptojacking network that mines the privacy coin Dero DERO.

According to a report by cybersecurity firm Kaspersky, the attack begins by exploiting publicly exposed Docker APIs over port 2375. Once access is gained, the malware spawns malicious containers. It infects already-running ones, siphoning system resources to mine Dero and scan for additional targets without requiring a central command server.

In software terms, a docker is a set of applications or platform tool and products that use OS-level virtualization to deliver software in small packages called containers.

The threat actor behind the operation deployed two Golang-based implants: one named “nginx” (a deliberate attempt to masquerade as the legitimate web server software), and another called “cloud,” which is the actual mining software used to generate Dero.

Once a host was compromised, the nginx module continuously scanned the internet for more vulnerable Docker nodes, using tools like Masscan to identify targets and deploy new infected containers.

“The entire campaign behaves like a zombie container outbreak,” researchers wrote. “One infected node autonomously creates new zombies to mine Dero and spread further. No external control is needed — just more misconfigured Docker endpoints.”

To avoid detection, it encrypts configuration data, including wallet addresses and Dero node endpoints, and hides itself under paths typically used by legitimate system software.

Kaspersky identified the same wallet and node infrastructure used in earlier cryptojacking campaigns that targeted Kubernetes clusters in 2023 and 2024, indicating an evolution of a known operation rather than a brand-new threat.

In this case, however, the use of self-spreading worm logic and the absence of a central command server make it especially resilient and harder to shut down.

As of early May, over 520 Docker APIs were publicly exposed over port 2375 worldwide — each one a potential target.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Analysis-From budgets to diplomacy, South Korea reels from martial law fallout as Trump looms
Analysis-From budgets to diplomacy, South Korea reels from martial law fallout as Trump looms
Dec 9, 2024
By Ju-min Park, Hyunjoo Jin, Cynthia Kim and Joyce Lee SEOUL (Reuters) - From trade and diplomacy to markets and budgets, South Korea struggled to contain the fallout from the president's brief but shocking martial law attempt last week, just as the country navigates an uncertain future with its ally the United States. Life largely went on without disturbance for...
NHTSA closes preliminary probe into 7,745 Fisker Ocean SUVs after software update
NHTSA closes preliminary probe into 7,745 Fisker Ocean SUVs after software update
Dec 9, 2024
Dec 9 (Reuters) - The U.S. auto safety regulator said on Monday it has closed a preliminary evaluation into 7,745 Fisker Ocean SUVs over failure to shift vehicles into the park gear, after the electric-vehicle startup issued recalls and released a software update. Earlier this year, the National Highway Traffic Safety Administration (NHTSA) opened a preliminary probe into claims of...
Intel should have focused on AI rather than chipmaking, TSMC founder says
Intel should have focused on AI rather than chipmaking, TSMC founder says
Dec 9, 2024
TAIPEI, Dec 9 (Reuters) - Intel ( INTC ) should have focused on artificial intelligence rather than trying to become a contract chipmaker, the founder of Taiwan Semiconductor Manufacturing Co ( TSM ) said on Monday, in relation to the recent departure of Intel's ( INTC ) CEO. Morris Chang, at an event to launch his autobiography, said he did...
Intel should have focused on AI rather than chipmaking, TSMC founder says
Intel should have focused on AI rather than chipmaking, TSMC founder says
Dec 9, 2024
TAIPEI (Reuters) - Intel ( INTC ) should have focused on artificial intelligence rather than trying to become a contract chipmaker, the founder of Taiwan Semiconductor Manufacturing Co ( TSM ) said on Monday, in relation to the recent departure of Intel's ( INTC ) CEO. Morris Chang, at an event to launch his autobiography, said he did not know...
Copyright 2023-2026 - www.financetom.com All Rights Reserved