Monero miners target cloud-native development environments :

Monero miners target cloud-native development environments


In the attack, hackers created several fake email accounts using a free Russian email service provider. They then set up a Bitbucket account with a few repositories. To evade detection, each masqueraded as a benign project using the official project documentation.
Hackers then created a Docker hub with several registries. Each registry presented itself as benign, using its documentation to evade detection. The images are built on these service providers’ environments and then hijack their resources to mine cryptocurrency.
“This campaign shows the ever-growing sophistication of attacks targeting the cloud-native stack,” says Assaf Morag of Aqua Security. “Bad actors are constantly evolving their techniques to hijack and exploit cloud compute resources for cryptocurrency mining. It also reminds us that developer environments in the cloud represent a lucrative target for attackers as usually, they are not getting the same level of security scrutiny.”

Related Keywords

Russia , Russian , Assaf Morag , Tim Mackey , Synopsys Cyrc Cybersecurity Research Centre , Docker Hub , Aqua Security , Cybersecurity Research Centre , ரஷ்யா , ரஷ்ய , ஸப் ம்ரக் , நேரம் மேக்கி , டாகர் மையம் , அக்வா பாதுகாப்பு , இணைய பாதுகாப்பு ஆராய்ச்சி மையம் ,

© 2025 Vimarsana