
Encore: LemonDucks evading detection.
CyberWire Daily
00:00
XR Crypto Miner on Docker Containers
It's very well masqueraded. So it starts off, you know, obviously someone has found these open APIs and then puts in a small file that basically then loads, they put the miner. And you'll notice this because CPU utilization on these Docker containers will start to rise. You'll also see it do some pretty interesting things in terms of not letting anyone else crypto mine on those instances as well. It kind of just cleans the kitchen to cook the duck.
Play episode from 06:21
Transcript


