Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The group operating Graboid are using malicious Docker containers hosted within the Docker Hub cloud repository to distribute the worm. Initial delivery is achieved via unsecured Docker daemons, the background processes that retrieve and execute the containers. Once they gain access, the group will install an initial instance of Graboid and provide it with a list of known vulnerable hosts from a command and control server.
Once deployed, this Graboid instance will connect to a Monero mining pool and begin mining. Whilst this is happening, it will select three hosts at random. The first target will have Graboid deployed to it, the second target will be sent a command to cease mining, with the third target instructed to begin mining again. At the time of publication, it is unclear why Graboid acts in this manner.
Remediation steps
| Type | Step |
|---|---|
|
If your organisation uses Docker, the following steps should be taken to secure your Docker daemons:
Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:59 pm