Unit 42 Finds the First Cryptojacking Docker Container Malware that spreads like a worm through the use of Docker containers. Malware is downloaded from an attacker’s command and control server and aims to mine for Monero. Traditional endpoint protection software does not inspect data and activities inside containers. 57.4% of the IPs originated from China, followed by 13% from the US. Unit 42 recommends some actions to prevent against compromise. They say to “Never expose a docker daemon to the internet without a proper authentication mechanism””]

