Doki
S0600 · Linux, Containers
Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms.
ATT&CK S0600
Sigma rules0
YARA rules0
Live IOCs0