Executive Summary
Doki is a Linux‑native backdoor that targets Docker containers in cloud environments, using a Dogecoin‑based DGA to evade detection. It establishes remote shells and may perform cryptocurrency mining on victim hosts.
Enhanced Description
Doki is a sophisticated Linux‑based backdoor that has been active since at least July 2020. It was discovered in association with the “ngrok Mining Botnet” and primarily targets Docker containers deployed on cloud platforms such as AWS, GCP, or Azure. The malware’s command‑and‑control (C2) infrastructure relies on a unique Dogecoin‑style Domain Generation Algorithm (DGA), which continuously produces new domain names that mimic cryptocurrency‑related traffic to evade detection. Once inside a container, Doki establishes persistence by creating system services and modifies startup scripts so it is automatically launched with each reboot. The backdoor exposes an interactive shell—often via TCP or SSH proxies—allowing adversaries to execute arbitrary commands, exfiltrate data, and download additional payloads. Its integration with ngrok channels also permits the malware to tunnel traffic through legitimate cloud services, further obscuring its presence. Beyond remote control, Doki is believed to conduct lightweight cryptocurrency mining, exploiting CPU resources of compromised containers for Dogecoin or similar altcoins. This dual function—command execution coupled with mining—extends its value chain: it can remain undetected while generating revenue and simultaneously provide a foothold for other attacks within the same environment.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is based solely on a brief description from Intezer, which confirms that Doki uses a Dogecoin‑based DGA and targets Docker containers. No in‑depth technical analysis or sample code was provided here, so details such as exact persistence mechanisms, file mutations, or mining payload specifics remain uncertain.
Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms. (Citation: Intezer Doki July 20)