Doki
MITRE ATT&CK: S0600 View on attack.mitre.org
Aliases: Doki
- First seen
- 2020-07-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux, containers
- Profile updated
- 2026-07-07 12:59:20
Targeted industries: technology-and-telecommunications
Context
Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms.
Detection coverage
- 204 Sigma rules
Malware & tools used
- Domain Generation Algorithms (attack-pattern)
- Escape to Host (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Deploy Container (attack-pattern)
- Unix Shell (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Web Service (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- External Remote Services (attack-pattern)
- Process Discovery (attack-pattern)
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Doki (report)
- intezer.com — Watch Your Containers Doki Infecting Docker Servers In The Cloud (report)
- securecoding.com — All About Doki Malware (report)
- MITRE ATT&CK — S0600 (report)
- intezer.com — Watch Your Containers Doki Infecting Docker Servers In The Cloud (report)