Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
NetworkAI-assisted

New Malware Attack Leveraging Exposed Docker APIs to Maintain Persistent SSH Root Access

Cybersecurity A new malware variant targeting exposed Docker APIs has been identified, showcasing advanced infection capabilities beyond traditional cryptomining activities. First discovered in August 2025, this malware employs evolved tactics to establish persistent root access, simultaneously preventing other attackers from…

New Malware Attack Leveraging Exposed Docker APIs to Maintain Persistent SSH Root Access

Cybersecurity

A new malware variant targeting exposed Docker APIs has been identified, showcasing advanced infection capabilities beyond traditional cryptomining activities.

First discovered in August 2025, this malware employs evolved tactics to establish persistent root access, simultaneously preventing other attackers from exploiting compromised systems.

This represents a significant evolution from a variant initially reported in June 2025.

The initial strain was primarily focused on cryptocurrency mining, utilizing Tor infrastructure. In contrast, the latest iteration demonstrates more complex behavior.

The attack begins by exploiting misconfigured Docker APIs accessible via the internet, specifically targeting port 2375, where Docker daemons are exposed without authentication.

The infection process involves creating malicious containers based on Alpine Linux images, which mount the host filesystem to gain privileged access.

This represents a significant evolution from a variant initially reported in June 2025.
Heather Lyons · Thehackingpost

A Base64-encoded payload is used to download and execute a shell script from a Tor hidden service, establishing multiple persistence mechanisms.

During honeypot monitoring, analysts identified this variant, noting distinct behavioral differences from previously documented attacks.

Advanced Persistence and Defense Evasion Mechanisms

The malware's notable advancement lies in its approach to maintaining exclusive access to compromised infrastructure.

Upon initial compromise, it deploys a script named docker-init.sh, which implements multiple layers of persistence and defense.

The persistence mechanism involves appending an attacker-controlled SSH public key to /root/.ssh/authorized_keys, enabling direct root access bypassing normal authentication.

Advertisement

Additionally, a cron job executes every minute, blocking access to port 2375 across various firewall platforms, including iptables, ufw, firewall-cmd, pfctl, and nft.

PORT=2375
PROTOCOL=tcp
for fw in firewall-cmd ufw pfctl iptables nft; do
  if command -v "$fw" >/dev/null 2>&1; then
    case "$fw" in
      firewall-cmd)
        firewall-cmd --permanent --zone=public --add-rich-rule="rule family='ipv4' port protocol='tcp' port='2375' reject"
        firewall-cmd --reload
    esac
  fi
done

This defensive measure prevents other malicious actors from exploiting the same vulnerability while maintaining the established foothold through SSH access.

The malware also installs tools for reconnaissance, such as masscan for network scanning and torsocks for anonymous communications.

These components enable the identification and compromise of additional vulnerable Docker instances, potentially leading to large-scale botnet operations.

The combination of persistent access, competitive exclusion, and propagation capabilities renders this malware a significant threat to containerized environments.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories