This new Linux malware targets some major victims: Docker, Apache Hadoop, Redis, and Confluence all under attack.

Hackers are exploiting misconfigured servers running Docker, Confluence, and other services to eliminate cryptocurrency miners.

Researchers at Cado Security Labs recently took a look at one such malware campaign and noted how threat actors are using multiple “unique and unreported payloads,” including four Golang binaries, to automatically discover Apache Hadoop YARN, Docker, Confluence and Redis, vulnerable to CVE. 2022-26134, a remote unauthenticated OGNL injection vulnerability that allows remote code execution.

scroll to top