An internet-reachable Docker API that an attacker can control can provide a path from a new container to the host. In a September 2025 incident report, Akamai described attackers using a misconfigured remote API to create a container, mount the host filesystem, and run malware. The report’s “lock-changing” behavior was persistence through altered SSH settings and a public key added to root’s authorized keys—not a reported password change.
How an exposed Docker API can lead to host access
Docker daemon control is administrative power. Docker says the daemon normally requires root privileges, and a container given a mount of a host directory can alter files in that directory. That means an attacker who can control a remotely exposed daemon may be able to use a container as a route to the host, rather than merely run code inside an isolated container. See Docker Engine security.
In the attack chain Akamai documented, attackers reached a misconfigured remote Docker API, created a container with the host filesystem mounted, and ran a downloaded shell script. The important distinction is that the report describes abuse of administrative API access and persistence; it does not describe a Docker Engine flaw that automatically compromises properly secured installations. Akamai’s report, by Yonatan Gilvarg, was published September 8, 2025: Off Your Docker: Exposed APIs Are Targeted in New Malware Strain.
What “changes the locks” meant in the 2025 report
In the earlier strain described by Akamai, the downloaded script used Tor to retrieve a payload, installed tools including Masscan and Torsocks, and downloaded the XMRig cryptocurrency miner. It also modified the host’s SSH configuration to permit root login and appended a public key to root’s authorized_keys. Those changes could give an attacker a way to reconnect over SSH. Akamai did not report that the attackers changed account passwords.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Akamai later observed a different variant. It blocked other parties from reaching the Docker API from the internet and had additional infection capabilities, but did not drop a cryptominer. The API-blocking behavior and the SSH/key changes are separate reported behaviors; they should not be merged into one checklist of actions performed by every variant.
How this differs from an older Docker campaign
A CERT-EU memo dated April 8, 2020 described a separate Docker cryptomining campaign involving exposed Docker Engine APIs, Kinsing malware, persistence, attempted lateral movement, and the kdevtmpfsi miner. The memo said the campaign had been active since at least March 2019 and reported “thousands of attempts taking place nearly on a daily basis” at the time, citing information published by Aqua Security. That is a historical activity figure, not a current estimate of exposed APIs or infections. Read the CERT-EU Threat Memo.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
| Report or variant | Reported payload or behavior |
|---|---|
| Akamai, earlier 2025 strain | Tor-based retrieval, Masscan and Torsocks tools, XMRig miner, SSH configuration changes, and a key added to root’s authorized keys. |
| Akamai, later 2025 variant | Blocked other internet users from reaching the Docker API; no cryptominer was dropped. |
| CERT-EU, 2020 campaign | Kinsing and the kdevtmpfsi miner; persistence and attempted lateral movement. |
How to reduce exposure when you operate Docker
If Docker control is needed only on the host
Prefer the local Unix socket and use traditional Unix permissions to limit who can access it. Granting access to Docker’s control interface is consequential because daemon control can affect the host; do not treat membership or access as a low-risk convenience.
If remote daemon access is necessary
Docker documents TLS certificates and SSH-based access alternatives. Keep the endpoint reachable only from trusted systems or a trusted network or VPN. Docker’s security guidance states: “Exposing the daemon API over HTTP without TLS is not permitted, and such a configuration causes the daemon to fail early on startup.” Use the controls together: authentication and protected transport do not make broad public reachability a good default, and network restriction is not a substitute for securing the API.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Docker also cautions that containers may still reach an endpoint even when a host firewall limits other network access. Account for container networking when assessing whether a firewall rule actually prevents access to the daemon. See Docker Engine security for the documented socket, TLS, SSH, and network guidance.
Check the current vendor advisory for a vulnerability
The 2024 Docker Engine AuthZ plugin regression is a separate issue from the malware activity Akamai reported in 2025. Docker said exploitation required API access and recommended updating and restricting that access. Do not infer that the regression caused the later campaign; consult Docker’s AuthZ Plugin Bypass Regression advisory for its scope and remediation.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
What to check if you suspect the daemon was abused
The indicators below follow artifacts described in Akamai’s report. They are useful checks, not a complete incident-response procedure.
- Look for unexpected containers and containers with host filesystem mounts.
- Review SSH daemon configuration for unexpected changes, including settings that permit root login.
- Inspect root’s
authorized_keysfor keys you do not recognize. - Investigate unexpected changes to whether the Docker API can be reached from the internet.
If an attacker controlled the daemon, treat the machine as potentially compromised at host level, not simply as a container that should be deleted. A host filesystem mount can expose host files to alteration; CERT-EU’s historical campaign analysis also discusses risks to hosted applications, the server, and adjacent systems. The documented indicators above do not establish whether a particular system is clean.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

