Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Doki

Doki

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Doki is a Linux‑native backdoor that targets Docker containers in cloud environments, using a Dogecoin‑based DGA to evade detection. It establishes remote shells and may perform cryptocurrency mining on victim hosts.

Enhanced Description

Doki is a sophisticated Linux‑based backdoor that has been active since at least July 2020. It was discovered in association with the “ngrok Mining Botnet” and primarily targets Docker containers deployed on cloud platforms such as AWS, GCP, or Azure. The malware’s command‑and‑control (C2) infrastructure relies on a unique Dogecoin‑style Domain Generation Algorithm (DGA), which continuously produces new domain names that mimic cryptocurrency‑related traffic to evade detection. Once inside a container, Doki establishes persistence by creating system services and modifies startup scripts so it is automatically launched with each reboot. The backdoor exposes an interactive shell—often via TCP or SSH proxies—allowing adversaries to execute arbitrary commands, exfiltrate data, and download additional payloads. Its integration with ngrok channels also permits the malware to tunnel traffic through legitimate cloud services, further obscuring its presence. Beyond remote control, Doki is believed to conduct lightweight cryptocurrency mining, exploiting CPU resources of compromised containers for Dogecoin or similar altcoins. This dual function—command execution coupled with mining—extends its value chain: it can remain undetected while generating revenue and simultaneously provide a foothold for other attacks within the same environment.

Key Capabilities

  • Creates persistence via systemd services and startup scripts
  • Establishes an interactive shell for remote command execution
  • Uses a unique Dogecoin‑based domain generation algorithm to contact its C2 infrastructure
  • Targets Linux containers running in cloud platforms (AWS, GCP, Azure)
  • Can download and execute additional payloads
  • May perform lightweight cryptocurrency mining on compromised hosts

ATT&CK Techniques

T1105
T1059.001
T1112
T1071.004

Recommended Actions

  • Implement network segmentation to isolate container ecosystems from core IT networks
  • Deploy runtime security solutions that detect anomalous outbound DNS queries, especially those following DGA patterns
  • Enable container image whitelisting and provenance checks for all Docker images
  • Monitor system processes for persistent services unrelated to legitimate workloads
  • Block suspicious domains identified as part of the Dogecoin DGA set via threat feeds or internal analysis
  • Apply timely OS and kernel patches on all Linux hosts and containers

Suggested Tags

Cryptocurrency Mining
Docker Container Attack
Domain Generation Algorithm
Linux Backdoor
Cloud Platform Targeting

Confidence Assessment

The intelligence is based solely on a brief description from Intezer, which confirms that Doki uses a Dogecoin‑based DGA and targets Docker containers. No in‑depth technical analysis or sample code was provided here, so details such as exact persistence mechanisms, file mutations, or mining payload specifics remain uncertain.

Description

Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms. (Citation: Intezer Doki July 20)

Details

Type
Malware
Platforms
Linux
Containers
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.