Skip to main content

Graboid Worm

Graboid is newly observed cryptocurrency mining worm that uses malicious Docker container images to propagate.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Graboid is newly observed cryptocurrency mining worm that uses malicious Docker container images to propagate.


Threat details

The group operating Graboid are using malicious Docker containers hosted within the Docker Hub cloud repository to distribute the worm. Initial delivery is achieved via unsecured Docker daemons, the background processes that retrieve and execute the containers. Once they gain access, the group will install an initial instance of Graboid and provide it with a list of known vulnerable hosts from a command and control server.

Once deployed, this Graboid instance will connect to a Monero mining pool and begin mining. Whilst this is happening, it will select three hosts at random. The first target will have Graboid deployed to it, the second target will be sent a command to cease mining, with the third target instructed to begin mining again. At the time of publication, it is unclear why Graboid acts in this manner.


Remediation steps

Type Step

If your organisation uses Docker, the following steps should be taken to secure your Docker daemons:

  • Do not download or deploy Docker containers from unidentified registries or users.
  • Use SSH or an HTTPS socket to connect to Docker daemons remotely.
  • Implement suitable firewall rules to limit incoming traffic to Docker daemons.
  • Perform frequent reviews of the Docker containers present on your systems.

Additionally, to prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 14 February 2020 2:59 pm