Exposed: New Docker Malware Hijacks Teneo Web3 Nodes for Crypto Profits Through Deceptive Signals


# New Cryptojacking Campaign Targets Docker Environments Using Teneo Network

Cybersecurity researchers from Darktrace and Cado Security have uncovered a sophisticated malware campaign targeting Docker environments with a novel cryptocurrency mining technique. Unlike traditional cryptojacking operations that deploy miners such as XMRig, this campaign leverages the Teneo decentralized physical infrastructure network (DePIN).

The attack begins when threat actors launch a container image called “kazutod/tene:ten” from Docker Hub. This image, uploaded two months ago and downloaded 325 times, contains a heavily obfuscated Python script that requires 63 unpacking iterations to reveal its actual code.

Once executed, the malware establishes a connection to teneo[.]pro. Rather than performing legitimate social media scraping functions, the script merely sends keep-alive pings to accumulate Teneo Points, which can later be converted to $TENEO tokens.

“The malware script simply connects to the WebSocket and sends keep-alive pings in order to gain more points from Teneo and does not do any actual scraping,” Darktrace explained. “Most of the rewards are gated behind the number of heartbeats performed, which is likely why this works.”

This campaign shares similarities with other malicious activities, including those using 9Hits Viewer software to generate traffic to specific websites and proxyjacking schemes that monetize unused internet bandwidth.

In related news, Fortinet FortiGuard Labs has identified a new botnet called RustoBot that exploits vulnerabilities in TOTOLINK and DrayTek devices to conduct DDoS attacks, primarily targeting technology sectors in Japan, Taiwan, Vietnam, and Mexico.

Security researcher Vincent Li notes: “IoT and network devices are often poorly defended endpoints, making them attractive targets for attackers to exploit and deliver malicious programs. Strengthening endpoint monitoring and authentication can significantly reduce the risk of exploitation.”

Share This Article