Tags
WormCryptominer
Incidents
Cetus campaign
References
https://unit42.paloaltonetworks.com/cetus-cryptojacking-worm/
Last edited
May 30, 2024 3:40 PM
Cetus is a cryptojacking worm named after a Greek mythology monster that disguises itself as a harmless whale. It masquerades as legitimate binaries commonly used in Docker environments, specifically Portainer, a UI tool for managing multiple Docker instances. The miner deployed by Cetus, XMRig, is disguised as "docker-cache," a plausible yet non-existent binary. Cetus also employs Masscan to randomly scan subnets for Docker daemons, infecting them by sending requests to the daemon’s API via the Docker CLI tool.