Hackers are using Dogecoin , the meme - themed cryptocurrency that recently experienced abull run thanks to TikTokkers , to facilitate amplify a malware botnet .
A new exploit called Doki is piggybacking on software that targets unprotected Docker containers . By pointing their botnet at a specific Dogecoin wallet , drudge are modify the command and control address for various septic Linux machine , ensuring no one can take over and stop the internet .
“ Recently , we have detected a novel malware lading that is different from the standard cryptominers typically deploy in this attack . The malware is a to the full undetected backdoor which we have named Doki , ” wrote security measures research worker atIntezer . “ Doki uses a antecedently undocumented method to contact its operator by abusing the Dogecoin cryptocurrency blockchain in a unique way in monastic order to dynamically generate its C2 domain address . ”

Photo: Christopher Furlong / Staff (Getty Images)
The system , while convoluted , is fairly ingenious . Because you do n’t require to admit someone to take over your C&C infrastructure , a botnet has to communicate fresh domain names to nodes whenever the system is compromised . Sometimes this is address is hardcoded into the botnet , or users can exchange it manually via a remote connecter . Neither solution is idealistic from the botnet operator ’s point of view as it can discover the hack to authority .
This novel system count at a certain Dogecoin billfold and watches for transactions . The system encode these transactions , extracts a snippet of each , and then create a new knowledge base — something like “ 6d77335c4f23[.]ddns[.]net”—that the botnet control can utilise to wield the infected server . Because it is based on a unassailable and tamper - proof crypto wallet , there is no way to tell what the next C&C waiter will be call .
“ Using this technique the aggressor controls which speak the malware will contact by transfer a specific amount of Dogecoin from his or her wallet . Since only the attacker has ascendence over the wallet , only he can ensure when and how much dogecoin to transfer , and thus flip the domain consequently . Additionally , since the blockchain is both changeless and decentralised , this novel method can prove to be quite springy to both infrastructure takedown from law enforcement and world filtering try from security products , ” write researcher Nicole Fishbein .

It just move to show you that the blockchain is good for something — crime !
botnetsDogecoinDogs
Daily Newsletter
Get the best tech , skill , and culture news in your inbox daily .
news show from the future tense , save to your present .
You May Also Like














![]()