Hackers are looking for unsecured Docker deployments where they can mine cryptocurrency. If an attacker can run a rogue container that mines for bitcoin, they can probably run containers that do worse things. We deployed a virtual machine, installed docker on it and exposed it to the internet. It took roughly two days until we noticed interesting traffic – someone took the bait. We wanted to focus on how an attacker might deploy a container with the intent of running it, but without actually running it. We configured Aqua CSP to block containers from running.”]
Source: https://blog.aquasec.com/cryptocurrency-miners-abusing-containers-anatomy-of-an-attempted-attack

