Find notable cyber news and cases, enriched with sources, timelines, and signals.

Exposed Docker API malware botnet-building tooling

Malware Activity
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

Updated malware targeting exposed Docker APIs now self-replicates, establishes persistent SSH access, and blocks port 2375, raising the risk of a durable botnet across compromised hosts. The chain uses Tor hidden services to fetch docker-init.sh and pulls system-linux-ARCH.zst as a second-stage payload. It also installs masscan, zstd, libpcap, and torsocks to support scanning, propagation, and evasion. Dormant logic for Telnet and Chrome remote debugging suggests room for future credential theft and browser hijacking.

Related Happenings

PCPJack Linux cloud credential-theft and persistence framework

Malware Activity
First: 07.05.2026 21:35 Last: 07.05.2026 21:35 Sources 1

About this happening: The **PCPJack** malware framework is stealing credentials from **exposed Linux cloud systems**, creating a broad risk of account takeover and lateral movement. It targets services...

PCPJack worm-like credential theft framework

Malware Activity
First: 07.05.2026 20:45 Last: 07.05.2026 20:45 Sources 1

About this happening: The **PCPJack** malware framework now conducts **credential theft** across exposed cloud infrastructure, raising the risk of account takeover and follow-on intrusion. It matters b...

Quasar Linux (QLNX) Linux RAT targeting developer credentials

Malware Activity
First: 06.05.2026 12:48 Last: 06.05.2026 12:48 Sources 1

About this happening: The **Quasar Linux (QLNX)** RAT has been identified as a **Linux backdoor** that can steal **developer credentials** and compromise software-supply-chain publishing pipelines. It...

CanisterWorm self-propagation across npm packages

Malware Activity
First: 21.03.2026 09:28 Last: 21.03.2026 09:28 Sources 1

About this happening: A **self-propagating npm supply-chain worm** tracked as **CanisterSprawl** is abusing **stolen developer npm tokens** to spread through compromised packages. **Socket** and **Step...

GhostLoader RAT-stealer via @openclaw-ai/openclawai

Malware Activity
First: 09.03.2026 20:31 Last: 09.03.2026 20:31 Sources 1

About this happening: A malicious **@openclaw-ai/openclawai** npm package is delivering **GhostLoader** to **macOS** hosts, enabling **credential theft**, **browser-session cloning**, and persistent re...

Timeline

  1. 09.09.2025 22:16 2 articles · 8mo ago

    Akamai finds Tor-based Docker API malware that blocks port 2375

    Technical Analysis Update

    Akamai researchers discovered updated malware targeting exposed Docker APIs that uses a Tor hidden service, downloads a second-stage script, installs scanning and evasion tools, and can block external access to compromised Docker API ports while supporting botnet-style self-replication and persistence on affected Docker hosts.

    Show sources