CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and Kubernetes infrastructure using an obscure domain from the payload, container escape attempt and anonymized “dog” mining pools.
Executive Summary
Kiss-a-Dog is a threat actor linked to a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. The actor exploits container vulnerabilities and uses obscure domains and anonymized mining pools to evade detection. This campaign highlights risks to cloud-native environments and underscores the need for robust container security measures.
Goals & Targeting
Kiss-a-Dog's primary objective appears to be financial gain through cryptocurrency mining. The actor specifically targets sectors heavily reliant on containerized infrastructure, such as cloud services, DevOps, and software development, where vulnerabilities in Docker and Kubernetes configurations are prevalent. By exploiting these environments, the group can leverage the computational resources of victim systems to mine cryptocurrency without direct interaction from victims. The lack of known geopolitical motives suggests a criminally motivated approach focused on monetizing infrastructure weaknesses.
Enhanced Description
CrowdStrike identified the 'Kiss-a-Dog' campaign, a cryptojacking operation that exploits misconfigured or vulnerable Docker and Kubernetes deployments. The threat actor leverages container escape techniques to gain access to host systems, then deploys cryptocurrency mining payloads. A key indicator is the use of an obscure domain within the payload, suggesting an effort to avoid detection by security tools. Anonymized mining pools with 'dog' in their names are used to obscure the actor's infrastructure. The campaign highlights a growing trend of adversaries targeting cloud-native technologies, where misconfigurations and unpatched vulnerabilities are common. The use of container-based infrastructure as a vector underscores the need for stricter security controls in DevOps environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Kiss-a-Dog's campaigns are characterized by a focus on containerized infrastructure, leveraging misconfigurations and unpatched vulnerabilities in Docker and Kubernetes environments. The actor's use of obscure domains and anonymized pools suggests an effort to operate covertly and avoid attribution. Operational tempo appears to be low-and-slow, prioritizing stealth over rapid lateral movement. Notably, no prior campaigns or actor affiliations have been publicly attributed to this group, indicating it may be an emerging threat.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the actor's association with the described techniques is moderate, based on CrowdStrike's attribution. However, limited information on the group's sophistication, affiliations, or long-term objectives reduces confidence in broader strategic motives. Gaps include unconfirmed indicators of compromise (IOCs), lack of historical campaign data, and unclear links to other known threat groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics