|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
專家警告稱,駭客正在瞄準易受攻擊的 Docker 遠端 API 伺服器,並利用它們在底層硬體上挖掘加密貨幣。

Hackers are targeting vulnerable Docker remote API servers, and using them to mine cryptocurrencies on the underlying hardware, experts have warned.
專家警告稱,駭客正在瞄準易受攻擊的 Docker 遠端 API 伺服器,並利用它們在底層硬體上挖掘加密貨幣。
Cybersecurity researchers from Trend Micro stated the crooks took an “unconventional approach” with this attack, noting, "The threat actor used the gRPC protocol over h2c to evade security solutions and execute their crypto mining operations on the Docker host."
趨勢科技的網路安全研究人員表示,騙子在這次攻擊中採取了“非常規方法”,並指出,“威脅行為者使用h2c 上的gRPC 協議來逃避安全解決方案,並在Docker 主機上執行加密挖掘操作。
"The attacker first checked the availability and version of the Docker API, then proceeds with requests for gRPC/h2c upgrades and gRPC methods to manipulate Docker functionalities."
“攻擊者首先檢查 Docker API 的可用性和版本,然後繼續請求 gRPC/h2c 升級和 gRPC 方法來操縱 Docker 功能。”
Which tokens are they mining?
他們正在開採哪些代幣?
The experts explained that the crooks would first seek out public-facing Docker API hosts where HTTP/2 protocol can be upgraded. Then, they would send out a request to upgrade to the h2c protocol which, after conclusion, allows them to create a container. That container is ultimately used to mine cryptocurrencies for the attackers, via the SRBMiner payload, hosted on GitHub.
專家解釋說,騙子首先會尋找可以升級 HTTP/2 協定的面向公眾的 Docker API 主機。然後,他們會發出升級到 h2c 協定的請求,該協定結束後,允許他們建立一個容器。該容器最終用於透過 GitHub 上託管的 SRBMiner 負載為攻擊者挖掘加密貨幣。
The researchers added the crooks used SRBMiner to mine the XRP token, native to the Ripple blockchain built by the company of the same name. However, XRP is a minted token that cannot be mined. We asked Trend Micro for clarification.
研究人員補充說,詐騙者使用 SRBMiner 來挖掘 XRP 代幣,該代幣源自同名公司建立的 Ripple 區塊鏈。然而,XRP 是一種鑄造代幣,無法開採。我們要求趨勢科技做出澄清。
SRBMiner uses algorithms like RandomX, KawPow for mining. It can generate a number of different tokens for its operators, but not XRP. Among the available tokens are Monero, Ravencoin, Haven Protocol, Wownero, and Firo.
SRBMiner 使用 RandomX、KawPow 等演算法進行挖礦。它可以為其運營商產生許多不同的代幣,但不能產生 XRP。可用的代幣包括 Monero、Ravencoin、Haven Protocol、Wownero 和 Firo。
It’s safe to assume that the crooks were actually mining Monero, one of the most popular tokens among cybercriminals, given its advanced privacy and anonymity features. Monero is also commonly mined via the XMRig cryptojacker, and its ticker is XRM, quite close to XRP.
可以肯定的是,騙子實際上正在挖掘門羅幣,而門羅幣是網路犯罪分子中最受歡迎的代幣之一,因為它具有先進的隱私和匿名功能。門羅幣也通常透過 XMRig 加密劫持者開採,其股票代號為 XRM,與 XRP 非常接近。
Trend Micro warned all users to secure their Docker remote API servers by implementing stronger access controls and authentication mechanisms, thus barring access to unauthenticated individuals. Furthermore, users are advised to monitor the servers for unusual activities, and implement best practices for container security.
趨勢科技警告所有使用者透過實施更強大的存取控制和身分驗證機制來保護其 Docker 遠端 API 伺服器,從而禁止未經身份驗證的個人存取。此外,建議使用者監控伺服器的異常活動,並實施容器安全的最佳實務。
Via The Hacker News
透過駭客新聞
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































