cognitive cybersecurity intelligence

News and Analysis

Search

Attackers Target Exposed Docker Remote API Servers With perfctl Malware

Cybersecurity firm Trend Micro has reported that an unidentified threat actor is abusing unprotected Docker Remote API servers to carry out perfctl malware attacks. The threat begins with probing and payload execution, then a Docker container is created with specific settings and a Base64 encoded payload is executed. This allows the creation of a bash script, setting of environment variables, and the downloading of a malicious binary disguised as a PHP extension.

Source: www.trendmicro.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts