Hackers are using misconfigured Docker API instances to build a botnet for mining the Dero cryptocurrency.
Security researchers discovered a 'container zombie outbreak' originating from exposed Docker APIs, leading to compromised and new containers used for cryptocurrency mining and propagation.
The attack involves malware disguised as 'nginx' that scans for vulnerable instances, infects them, creates new malicious containers, and forces existing ones to mine Dero, all autonomously.
Users of Docker are advised to secure their API settings, fortify login credentials, and conduct regular security audits to prevent such attacks.