Doki

MITRE ATT&CK: S0600 View on attack.mitre.org

Aliases: Doki

First seen
2020-07-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
linux, containers
Profile updated
2026-07-07 12:59:20

Targeted industries: technology-and-telecommunications

Context

Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms.

Detection coverage

  • 204 Sigma rules

Malware & tools used

  • Domain Generation Algorithms (attack-pattern)
  • Escape to Host (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Deploy Container (attack-pattern)
  • Unix Shell (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Web Service (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • External Remote Services (attack-pattern)
  • Process Discovery (attack-pattern)

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Doki (report)
  • intezer.com — Watch Your Containers Doki Infecting Docker Servers In The Cloud (report)
  • securecoding.com — All About Doki Malware (report)
  • MITRE ATT&CK — S0600 (report)
  • intezer.com — Watch Your Containers Doki Infecting Docker Servers In The Cloud (report)

External references