Malware developed by hacker group TeamTnT targets exposed Docker daemon APIs to perform scanning and cryptojacking operations. Black-T includes features not found in the groups earlier malware, including targeting and stopping of previously unknown Cryptojacking worms – the Crux worm, ntpd miner and a redis-backup miner. The group leveraged Weave Scope – an open-source cloud monitoring tool from Weave Works that integrates with Docker, Kubernetes and Amazon Web Services.”]
Source: https://www.databreachtoday.com/cryptojacker-targets-exposed-docker-daemon-apis-a-15116