Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Kiss-a-Dog

Description

CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and Kubernetes infrastructure using an obscure domain from the payload, container escape attempt and anonymized “dog” mining pools.

AI Analysis

· 1 week ago

Executive Summary

Kiss-a-Dog is a threat actor linked to a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. The actor exploits container vulnerabilities and uses obscure domains and anonymized mining pools to evade detection. This campaign highlights risks to cloud-native environments and underscores the need for robust container security measures.

Goals & Targeting

Kiss-a-Dog's primary objective appears to be financial gain through cryptocurrency mining. The actor specifically targets sectors heavily reliant on containerized infrastructure, such as cloud services, DevOps, and software development, where vulnerabilities in Docker and Kubernetes configurations are prevalent. By exploiting these environments, the group can leverage the computational resources of victim systems to mine cryptocurrency without direct interaction from victims. The lack of known geopolitical motives suggests a criminally motivated approach focused on monetizing infrastructure weaknesses.

Enhanced Description

CrowdStrike identified the 'Kiss-a-Dog' campaign, a cryptojacking operation that exploits misconfigured or vulnerable Docker and Kubernetes deployments. The threat actor leverages container escape techniques to gain access to host systems, then deploys cryptocurrency mining payloads. A key indicator is the use of an obscure domain within the payload, suggesting an effort to avoid detection by security tools. Anonymized mining pools with 'dog' in their names are used to obscure the actor's infrastructure. The campaign highlights a growing trend of adversaries targeting cloud-native technologies, where misconfigurations and unpatched vulnerabilities are common. The use of container-based infrastructure as a vector underscores the need for stricter security controls in DevOps environments.

Key Capabilities

  • Container escape exploits
  • Exploitation of Docker/Kubernetes vulnerabilities
  • Use of obscure, anonymized domains for command-and-control (C2)
  • Deployment of cryptocurrency mining payloads
  • Obfuscation of infrastructure via anonymized mining pools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1132.001 - Exploit Public-Facing Application - Web Application
T1059.003 - Command and Scripting Interpreter: PowerShell
T1566.001 - Phishing - Spearphishing Attachment
T1026 - Exploitation of Vulnerability
T1547.001 - Child Process: Hidden

Software / Tooling

Custom cryptojacking malware
Container escape exploits
Anonymized mining pool infrastructure

Campaigns & Victims

Kiss-a-Dog's campaigns are characterized by a focus on containerized infrastructure, leveraging misconfigurations and unpatched vulnerabilities in Docker and Kubernetes environments. The actor's use of obscure domains and anonymized pools suggests an effort to operate covertly and avoid attribution. Operational tempo appears to be low-and-slow, prioritizing stealth over rapid lateral movement. Notably, no prior campaigns or actor affiliations have been publicly attributed to this group, indicating it may be an emerging threat.

IOC Patterns

  • Spear-phishing with malicious Office documents targeting DevOps personnel
  • C2 communication over DNS with fast-flux infrastructure
  • Staging of infrastructure on bulletproof hosting services
  • Use of mining pools with names containing 'dog' (e.g., 'dog-pool.com')

Recommended Actions

  • Audit and patch Docker/Kubernetes configurations to prevent container escape
  • Implement network segmentation to isolate container hosts from critical infrastructure
  • Monitor for anomalous CPU usage patterns indicative of cryptojacking
  • Deploy endpoint detection tools with container-specific threat signatures
  • Blocking domains associated with anonymized mining pools in network firewalls

Suggested Tags

APT
cryptojacking
cloud-sector
container-escape

Confidence Assessment

Confidence in the actor's association with the described techniques is moderate, based on CrowdStrike's attribution. However, limited information on the group's sophistication, affiliations, or long-term objectives reduces confidence in broader strategic motives. Gaps include unconfirmed indicators of compromise (IOCs), lack of historical campaign data, and unclear links to other known threat groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
cryptojacking
cloud-sector
container-escape

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.