{"id":1701,"date":"2025-04-23T12:31:15","date_gmt":"2025-04-23T12:31:15","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=1701"},"modified":"2025-04-23T12:31:15","modified_gmt":"2025-04-23T12:31:15","slug":"new-malware-hijacks-docker-photographs-utilizing-distinctive-obfuscation-method","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=1701","title":{"rendered":"New Malware Hijacks Docker Photographs Utilizing Distinctive Obfuscation Method"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A just lately uncovered malware marketing campaign focusing on Docker, probably the most steadily attacked companies in keeping with Darktrace\u2019s honeypot knowledge, has revealed a startling degree of sophistication in obfuscation and cryptojacking strategies. <\/p>\n<p>This novel assault begins with a seemingly innocuous request to launch a container from Docker Hub, particularly the kazutod\/tene:ten picture. <\/p>\n<h2 class=\"wp-block-heading\"><strong>Subtle Assault Targets Docker Hub with Superior Payload Hiding<\/strong><\/h2>\n<p>By leveraging Docker\u2019s built-in instruments to drag and extract the picture layers, analysts found that the container executes a Python script named ten.py. <\/p>\n<div class=\"td-a-ad id_inline_ad0 id_ad_content-horiz-center\"><span class=\"td-adspot-title\">&#8211; Commercial &#8211;<\/span><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgtF4v5Ejzb9hD6O8UG7KJJziqO1ZP5zcUuKXNsyjb4g3FugqSKlBjBKmUNqGCjtqOq8kEb1lM6uZOBXm0lUCSTqXKyP4hz81q77L_k5I4RBy3afKYWuunQXOVo9zA4MFlD75XmYOjxT0sNIO9RR8UZPin1ZBVShx5Xj-5D9SyEp0QgEPoA6vxXp3Q4DInb\/s16000\/Don%E2%80%99t%20miss%20our%20latest%20stories%20on%20Google%20News%20(1).png&#10;\" alt=\"Google News\"\/><\/a><\/div>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiPTRLAyH6ZSZ-bbnImMSche1iaJ5aktqfp22lTU17LqMRaWpof7JDlwG343etTFAOAt-TXJ_UYpFeu3UWsmb8qAtp2DC-RecmYDIc3cI0fdT-nYMNrLayR0CD0Ynfn1oEo5bLN1gSCoSlf2yFGIvLdDX7LLR6xnHjFyPGz4nzkcNzm2jQUB2tNf3KrdKg\/s16000\/Use%20of%20Cyberchef%20to%20decode%20the%20ten.py%20script.webp\" alt=\"Docker Images\"\/><figcaption class=\"wp-element-caption\">Use of Cyberchef to decode the\u00a0<em>ten.py<\/em>\u00a0script.<\/figcaption><\/figure>\n<\/div>\n<p>What units this marketing campaign aside is the intricate obfuscation approach used to hide the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/koiloader-exploits-powershell-scripts-to-drop\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious payload<\/a> inside this script. <\/p>\n<p>The script employs a multi-layered method, using a lambda perform to reverse a base64-encoded string, decode it, and decompress it by way of zlib earlier than executing the end result as Python code. <\/p>\n<p>This course of repeats over 63 iterations, a deliberate tactic that doubtless goals to thwart signature-based detection and frustrate reverse-engineering efforts by analysts.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Cryptojacking Evolves with Decentralized Community Exploitation<\/strong><\/h2>\n<p>Delving deeper into the de-obfuscated code, the malware\u2019s intent turns into clear: it establishes a connection to teneo[.]professional, a legit Web3 startup targeted on decentralized knowledge networks. <\/p>\n<p>Teneo incentivizes customers to hitch its community with \u201cTeneo Factors,\u201d a non-public crypto token, in change for working nodes that scrape social media knowledge. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgZA9W6TYyjVAtPOLyuP277DjgnIYJCdv30xbO6SU9zYAUQdby7fwdl4I1iYsIdNSQZ88sv6My8GgoZzxIGXO7QqwdiVWxWyR3zdjmrUksgNg19UxiBLDG1PV4vvzAYwcjlIUhwTS0Ae7r84VkYzC6KorIiF2QrSgNlqUtDohxSLR5j-cnE-XanH4DWGwY\/s16000\/Extraction%20of%20the%20resulting%20tar%20file.webp\" alt=\"Docker Images\"\/><figcaption class=\"wp-element-caption\">Extraction of the ensuing tar file.<\/figcaption><\/figure>\n<\/div>\n<p>Nonetheless, this malware exploits the system by connecting by way of a websocket and sending keep-alive pings with out performing any scraping, illicitly accumulating factors primarily based on heartbeat counts. <\/p>\n<p>This represents a shift from conventional cryptojacking instruments like XMRig, which immediately mine <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/legality-of-cryptocurrencies\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrencies <\/a>and are broadly detected by safety techniques. <\/p>\n<p>As an alternative, attackers are actually hijacking legit decentralized platforms for revenue, a pattern additionally evident within the attacker\u2019s Docker Hub profile, the place related containers execute purchasers for different distributed networks like Nexus. <\/p>\n<p>The profitability of this technique stays unsure as a result of opaque nature of personal tokens and the shortage of public pricing knowledge, as seen with Teneo\u2019s token listed as \u201cpreview solely\u201d on CoinGecko.<\/p>\n<p>Based on the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.darktrace.com\/blog\/obfuscation-overdrive-next-gen-cryptojacking-with-layers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report<\/a>, this marketing campaign underscores the persistent evolution of malware techniques, notably within the realm of obfuscation and cryptojacking.<\/p>\n<p>The extreme layering of encoded payloads, whereas seemingly pointless for bypassing detection, highlights the lengths to which risk actors will go to guard their code from scrutiny. <\/p>\n<p>For system directors, this serves as a important reminder of Docker\u2019s vulnerability as a major goal. <\/p>\n<p>Exposing Docker companies to the web with out strong authentication and firewall protections is a recipe for compromise, as assaults happen with alarming frequency. Even temporary publicity can result in vital breaches. <\/p>\n<p>As attackers proceed to innovate by abusing legit instruments for illicit achieve, the necessity for superior detection mechanisms and proactive safety measures has by no means been extra pressing. <\/p>\n<p>This case not solely illustrates the significance of de-obfuscation expertise for analysts but in addition indicators a broader shift within the cyberthreat panorama, the place conventional assault vectors are changed by insidious, covert methods.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><strong>Discover this Information Fascinating! Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, &amp;\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Prompt Updates!<\/strong><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A just lately uncovered malware marketing campaign focusing on Docker, probably the most steadily attacked companies in keeping with Darktrace\u2019s honeypot knowledge, has revealed a startling degree of sophistication in obfuscation and cryptojacking strategies. This novel assault begins with a seemingly innocuous request to launch a container from Docker Hub, particularly the kazutod\/tene:ten picture. Subtle [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1703,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1400,1651,130,216,1653,1654,1652],"class_list":["post-1701","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-docker","tag-hijacks","tag-images","tag-malware","tag-obfuscation","tag-technique","tag-unique"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1701"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1701\/revisions"}],"predecessor-version":[{"id":1702,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/1701\/revisions\/1702"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/1703"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 10:10:10 UTC -->