New Cryptojacking Attack Targets Docker API to Create Malicious Swarm BotnetThe Hacker News·Oct 1, 06:22 UTC · Oct 1, 2024Malware142
Crooks exploit exposed Docker APIs to build AESDDoS botnetSecurity Affairs·Jun 15, 22:27 UTC · Jun 15, 2019MalwareCVE-2019-5736147
Python Malware Poses DDoS Threat Via Docker API MisconfigurationInfosecurity Magazine·Nov 13, 16:30 UTC · Nov 13, 2023Malware142
Dero miner spreads inside containerized Linux environmentsKaspersky Securelist·May 21, 10:00 UTC · May 21, 2025Malware42
New XORDDoS, Kaiji DDoS botnet variants target Docker serversSecurity Affairs·Jun 24, 06:54 UTC · Jun 24, 2020Malware142
New Self-Spreading Malware Infects Docker Containers to Mine Dero CryptocurrencyThe Hacker News·May 27, 16:23 UTC · May 27, 2025Malware42
Millions of Malicious Containers Found on Docker HubInfosecurity Magazine·Apr 30, 14:30 UTC · Apr 30, 2024Malware42
Doki, an undetectable Linux backdoor targets Docker ServersSecurity Affairs·Jul 29, 12:21 UTC · Jul 29, 2020Malware142
Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 YearsThe Hacker News·May 4, 08:19 UTC · May 4, 2024Malware42
30 Docker images downloaded 20M times in cryptojacking attacksSecurity Affairs·Mar 30, 07:57 UTC · Mar 30, 2021Malware42
TeamTNT botnet now steals Docker API and AWS credentialsSecurity Affairs·Jan 10, 10:22 UTC · Jan 10, 2021Malware142
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply ChainThe Hacker News·Apr 24, 04:35 UTC · Apr 24, 2026Malware42
Linux Malware targets misconfigured misconfigured Apache Hadoop, Confluence, Docker, and Redis serversSecurity Affairs·Mar 7, 07:30 UTC · Mar 7, 2024Malware142
Linux Malware Targets Docker, Apache Hadoop, Redis and ConfluenceInfosecurity Magazine·Mar 6, 16:15 UTC · Mar 6, 2024MalwareCVE-2022-26134147
Experts Warn of Impending TeamTNT Docker AttacksInfosecurity Magazine·Jul 6, 10:30 UTC · Jul 6, 2023Malware42
Lemon_Duck cryptomining botnet targets Docker serversSecurity Affairs·Apr 22, 07:26 UTC · Apr 22, 2022MalwareCVE-2020-079647
TeamTNT group uses Hildegard Malware to target Kubernetes SystemsSecurity Affairs·Feb 5, 16:44 UTC · Feb 5, 2021Malware42
Week in review: Docker Hub breach, identifying malware in embedded systems, CCPA implementationHelp Net Security·May 5, 00:00 UTC · May 5, 2019Malware142
Cybercriminals Are Using Legit Cloud Monitoring Tools As BackdoorThe Hacker News·Sep 9, 08:23 UTC · Sep 9, 2020Malware42
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes TokensThe Hacker News·Jul 17, 17:12 UTC · Jul 17, 2026MalwareCVE-2026-39987CVE-2026-41176CVE-2022-22947+1 CVEs47
TeamTNT's Silentbob Botnet Infecting 196 Hosts in Cloud Attack CampaignThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Malware42
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police AppSecurity Affairs·Jul 30, 22:43 UTC · Jul 30, 2026Malware42
Cryptojacking Gang TeamTNT Make a ComebackInfosecurity Magazine·Sep 19, 10:15 UTC · Sep 19, 2024Malware142
Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints AheadThe Hacker News·Aug 23, 11:52 UTC · Aug 23, 2023Malware42
TeamTNT Targeted Cloud Instances and Containerized Environments For Two YearsInfosecurity Magazine·Aug 26, 16:00 UTC · Aug 26, 2022Malware42
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP PacketsThe Hacker News·Oct 17, 04:34 UTC · Oct 17, 2025MalwareCVE-2024-2389747
Multi-Vector Miner+Tsunami Botnet with SSH Lateral MovementSecurity Affairs·Dec 2, 08:54 UTC · Dec 2, 2020MalwareCVE-2020-1488247
Connecting the dots between recently active cryptominersCisco Talos·Dec 18, 16:33 UTC · Dec 18, 2018Malware42
Hades PyPI Attack: 19 Packages Poisoned to AutoThe Hacker News·Jun 9, 10:34 UTC · Jun 9, 2026Malware142
Laravel-Lang PHP Packages Compromised to Deliver CrossThe Hacker News·May 24, 08:14 UTC · May 24, 2026Malware42
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain AttackThe Hacker News·May 15, 00:00 UTC · May 15, 2026Malware42
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & MoreThe Hacker News·Apr 28, 07:38 UTC · Apr 28, 2026MalwareCVE-2025-20333CVE-2025-20362CVE-2026-40372+20 CVEs147
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV FilesThe Hacker News·Mar 28, 06:25 UTC · Mar 28, 2026Malware42
TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malwareHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2026Malware42
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide MalwareInfosecurity Magazine·Mar 24, 14:30 UTC · Mar 24, 2026Malware42
‘CanisterWorm’ Springs Wiper Attack Targeting IranKrebs on Security·Mar 23, 19:04 UTC · Mar 23, 2026Malware42