Doki

S0600

Malware.View on attack.mitre.org

About this malware

Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1020
Automated Exfiltration

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

T1036.005
Match Legitimate Resource Name or Location

Doki has disguised a file as a Linux kernel module.

T1041
Exfiltration Over C2 Channel

Doki has used Ngrok to establish C2 and exfiltrate data.

T1057
Process Discovery

Doki has searched for the current process’s PID.

T1059.004
Unix Shell

Doki has executed shell scripts with /bin/sh.

T1071.001
Web Protocols

Doki has communicated with C2 over HTTPS.

T1083
File and Directory Discovery

Doki has resolved the path of a process PID to use as a script argument.

T1102
Web Service

Doki has used the dogechain.info API to generate a C2 address.

T1105
Ingress Tool Transfer

Doki has downloaded scripts from C2.

T1133
External Remote Services

Doki was executed through an open Docker daemon API port.

T1568.002
Domain Generation Algorithms

Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains.

T1573.002
Asymmetric Cryptography

Doki has used the embedTLS library for network communications.

T1610
Deploy Container

Doki was run through a deployed container.

T1611
Escape to Host

Doki’s container was configured to bind the host root directory.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Intezer Doki July 20 Open source
    Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.