Share this article

Privacy Crypto Dero Targeted With New Self-Spreading Malware

The malware spread like a worm and spawned malicious containers after infecting fresh devices.

May 28, 2025, 1:11 p.m.
A hooded figure sits typing on a laptop in a darkened (Pixabay)

What to know:

  • A new Linux malware campaign is targeting unsecured Docker infrastructure to create a cryptojacking network mining Dero.
  • The attack exploits exposed Docker APIs on port 2375, using malicious containers to mine cryptocurrency and spread without a central server.
  • Kaspersky reports that the malware uses Golang-based implants and encrypts data to avoid detection, indicating an evolution of previous cryptojacking operations.

A newly discovered Linux malware campaign is compromising unsecured Docker infrastructure worldwide, turning exposed servers into part of a decentralized cryptojacking network that mines the privacy coin Dero .

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

According to a report by cybersecurity firm Kaspersky, the attack begins by exploiting publicly exposed Docker APIs over port 2375. Once access is gained, the malware spawns malicious containers. It infects already-running ones, siphoning system resources to mine Dero and scan for additional targets without requiring a central command server.

In software terms, a docker is a set of applications or platform tool and products that use OS-level virtualization to deliver software in small packages called containers.

The threat actor behind the operation deployed two Golang-based implants: one named “nginx” (a deliberate attempt to masquerade as the legitimate web server software), and another called “cloud,” which is the actual mining software used to generate Dero.

Once a host was compromised, the nginx module continuously scanned the internet for more vulnerable Docker nodes, using tools like Masscan to identify targets and deploy new infected containers.

“The entire campaign behaves like a zombie container outbreak,” researchers wrote. “One infected node autonomously creates new zombies to mine Dero and spread further. No external control is needed — just more misconfigured Docker endpoints.”

To avoid detection, it encrypts configuration data, including wallet addresses and Dero node endpoints, and hides itself under paths typically used by legitimate system software.

Kaspersky identified the same wallet and node infrastructure used in earlier cryptojacking campaigns that targeted Kubernetes clusters in 2023 and 2024, indicating an evolution of a known operation rather than a brand-new threat.

In this case, however, the use of self-spreading worm logic and the absence of a central command server make it especially resilient and harder to shut down.

As of early May, over 520 Docker APIs were publicly exposed over port 2375 worldwide — each one a potential target.

More For You

KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

16:9 Image

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.

What to know:

  • KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
  • This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
  • Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
  • Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
  • Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.

More For You

Solana’s new phase is ‘much more about finance,’ says Backpack CEO Armani Ferrante

Backpack CEO Armani Ferrante (CoinDesk)

The Solana ecosystem has spent the past year doubling down on a financial infrastructure, Backpack CEO Armani Ferrante told CoinDesk.

What to know:

  • Solana’s latest phase looks a lot less flashy than its memecoin-fueled highs, and that may be the goal.
  • Armani Ferrante, CEO of crypto exchange Backpack, told CoinDesk in an interview the Solana ecosystem has spent the past year doubling down on a more sober focus: financial infrastructure. A
  • fter years of experimentation as the wider crypto industry focused on NFTs, games and social tokens, attention is now shifting back toward decentralized finance, trading and payments.