Exposed Docker API malware botnet-building tooling
Malware Activity
Summary
Hide ▲
Show ▼
Updated malware targeting exposed Docker APIs now self-replicates, establishes persistent SSH access, and blocks port 2375, raising the risk of a durable botnet across compromised hosts. The chain uses Tor hidden services to fetch docker-init.sh and pulls system-linux-ARCH.zst as a second-stage payload. It also installs masscan, zstd, libpcap, and torsocks to support scanning, propagation, and evasion. Dormant logic for Telnet and Chrome remote debugging suggests room for future credential theft and browser hijacking.
Related Happenings
PCPJack Linux cloud credential-theft and persistence framework
Malware Activity
First: 07.05.2026 21:35
Last: 07.05.2026 21:35
Sources 1
About this happening:
The **PCPJack** malware framework is stealing credentials from **exposed Linux cloud systems**, creating a broad risk of account takeover and lateral movement. It targets services...
PCPJack Linux cloud credential-theft and persistence framework
Malware ActivityAbout this happening: The **PCPJack** malware framework is stealing credentials from **exposed Linux cloud systems**, creating a broad risk of account takeover and lateral movement. It targets services...
PCPJack worm-like credential theft framework
Malware Activity
First: 07.05.2026 20:45
Last: 07.05.2026 20:45
Sources 1
About this happening:
The **PCPJack** malware framework now conducts **credential theft** across exposed cloud infrastructure, raising the risk of account takeover and follow-on intrusion. It matters b...
PCPJack worm-like credential theft framework
Malware ActivityAbout this happening: The **PCPJack** malware framework now conducts **credential theft** across exposed cloud infrastructure, raising the risk of account takeover and follow-on intrusion. It matters b...
Quasar Linux (QLNX) Linux RAT targeting developer credentials
Malware Activity
First: 06.05.2026 12:48
Last: 06.05.2026 12:48
Sources 1
About this happening:
The **Quasar Linux (QLNX)** RAT has been identified as a **Linux backdoor** that can steal **developer credentials** and compromise software-supply-chain publishing pipelines. It...
Quasar Linux (QLNX) Linux RAT targeting developer credentials
Malware ActivityAbout this happening: The **Quasar Linux (QLNX)** RAT has been identified as a **Linux backdoor** that can steal **developer credentials** and compromise software-supply-chain publishing pipelines. It...
CanisterWorm self-propagation across npm packages
Malware Activity
First: 21.03.2026 09:28
Last: 21.03.2026 09:28
Sources 1
About this happening:
A **self-propagating npm supply-chain worm** tracked as **CanisterSprawl** is abusing **stolen developer npm tokens** to spread through compromised packages. **Socket** and **Step...
CanisterWorm self-propagation across npm packages
Malware ActivityAbout this happening: A **self-propagating npm supply-chain worm** tracked as **CanisterSprawl** is abusing **stolen developer npm tokens** to spread through compromised packages. **Socket** and **Step...
GhostLoader RAT-stealer via @openclaw-ai/openclawai
Malware Activity
First: 09.03.2026 20:31
Last: 09.03.2026 20:31
Sources 1
About this happening:
A malicious **@openclaw-ai/openclawai** npm package is delivering **GhostLoader** to **macOS** hosts, enabling **credential theft**, **browser-session cloning**, and persistent re...
GhostLoader RAT-stealer via @openclaw-ai/openclawai
Malware ActivityAbout this happening: A malicious **@openclaw-ai/openclawai** npm package is delivering **GhostLoader** to **macOS** hosts, enabling **credential theft**, **browser-session cloning**, and persistent re...
Timeline
-
09.09.2025 22:16 2 articles · 8mo ago
Akamai finds Tor-based Docker API malware that blocks port 2375
Technical Analysis UpdateAkamai researchers discovered updated malware targeting exposed Docker APIs that uses a Tor hidden service, downloads a second-stage script, installs scanning and evasion tools, and can block external access to compromised Docker API ports while supporting botnet-style self-replication and persistence on affected Docker hosts.
Show sources
- Hackers hide behind Tor in exposed Docker API breaches — www.bleepingcomputer.com — 09.09.2025 22:16
- Hackers hide behind Tor in exposed Docker API breaches — www.bleepingcomputer.com — 09.09.2025 22:16