Pro-Ukraine hackers, possibly linked to Ukraine IT Army, are compromising Docker images to launch distributed denial-of-service (DDoS) attacks against several websites belonging to the Russian and Belarusian government, military, and media. The DDoS attacks also targeted three Lithuanian media websites.
The cybersecurity firm CrowdStrike observed the attack and discovered that the Docker Engine honeypots deployed between February 27 and March 1 were compromised and used in the DDoS attacks.
The attackers tried to exploit misconfigured Docker installs through exposed APIs and takeover them to abuse their computational resources.
Crowdstrike reported that container and cloud-based resources are being abused to deploy disruptive tools. The use of compromised infrastructure has far-reaching consequences for organizations who may unwittingly be participating in hostile activity against Russian government, military and civilian targets. Docker Engine honeypots were compromised to execute two different Docker images targeting Russian, Belarusian and Lithuanian websites in a denial-of-service (DoS) attack.
Financially-motivated threat actors, like LemonDuck or TeamTNT used the technique of compromising Docker containers in order to abuse their resources and mine cryptocurrencies.
According to the experts, the Docker images’ target lists overlap with domains shared by the Ukraine IT Army (UIA). The attacks involved the two images that have been downloaded more than 150,000 times, but the CrowdStrike Intelligence cannot determine the exact number of downloads originating from compromised infrastructure.
The list of targeted websites includes the Kremlin and Tass agency websites. The two images used by the attackers are named “erikmnkl/stoppropaganda” and “abagayev/stop-russia”.
CrowdStrike Intelligence evaluates that these actors almost certainly compromised the honeypots to support pro-Ukrainian DDoS attacks.
Image Credits : Crowdstrike














Comments