Honeypot capture
RedTail
Known family
Delivered through an exposed Docker API and captured whole, loader and competitor-removal script included. The miner runs fileless through memfd_create, carries an embedded SSH client and a libpcap sniffer, and self-replicates by dropping an SSH key.
- Family
- RedTail
- First seen
- June 2026
- Vector
- Exposed Docker API
- Format
- ~1.88 MB, multi-arch (x86_64 / i686 / aarch64 / arm7)
- VirusTotal
- Known family (active since late 2023); encrypted config, no embedded wallet
- Tags
- cryptominer · docker · worm · fileless
- Report
- Self-propagation through exposed Docker APIs
- Sample
- By request. Email [email protected]
SHA-256
-
59c29436755b0778e968d49feeae20ed65f5fa5e35f9f7965b8ed93420db91e5