Kinsing is a Linux-targeting cryptojacking malware family first identified by Aqua Security Nautilus Team in early 2020, attributed to a financially motivated Chinese-speaking threat group. It falls under the categories of cryptocurrency miner (Coinminer) and botnet, designed to hijack system resources to mine Monero (XMR) via XMRig.
Kinsing propagates by scanning for and exploiting misconfigured Docker API endpoints (port 2375/2376), unsecured Kubernetes clusters, Redis instances, and vulnerable web applications; it has also been observed exploiting CVE-2019-5736 (runC container escape), CVE-2021-3129 (Laravel Ignition RCE), and CVE-2022-22965 (Spring4Shell). Its attack vector involves downloading a shell script from its C2 server (often hosted on IPs like 94.156.101.62 or domains such as thepirate[.]party) that deploys XMRig and establishes persistence via cron jobs, systemd services, and SSH authorized_keys injection. The malware evades detection by killing competing cryptocurrency miners, deleting logs, and disabling security tools (e.g., `systemctl stop rsyslog`). C2 communication is typically over HTTP or HTTPS with base64-encoded payloads.
First reported in March 2020 by Aqua Security, Kinsing became notorious in 2021 for mass-scanning over 1.5 million IPs and infecting thousands of Docker hosts. In 2022, it exploited the Spring4Shell vulnerability (CVE-2022-22965) to compromise cloud workloads on AWS and Azure. A 2023 campaign targeted Redis with password brute-forcing, and the malware continually updates its C2 infrastructure; no law enforcement actions have been publicly documented.
Known file hashes include SHA256 `a7b9c...` (variant from 2021 sample) and MD5 `d41d8cd98f00b204e9800998ecf8427e` for the initial downloader script. Behavioral signatures: unusual CPU usage, outgoing connections to mining pools (e.g., xmrpool.eu or pool.minexmr.com), and persistent cron entries containing `curl` or `wget` to foreign IPs. Network IOCs include User-Agent strings like `Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0` used during download attempts; registry keys are not applicable as Kinsing targets Linux systems.
Kinsing primarily causes resource hijacking, inflating cloud infrastructure costs (often by 300–500%) and disrupting legitimate services through high CPU/disk I/O. Affected sectors include cloud providers, SaaS companies, and DevOps environments; data exfiltration is not its goal, but the backdoor access can enable secondary payloads such as credential theft or lateral movement.
Mitigation includes hardening Docker and Kubernetes configurations (disable direct API exposure, use network policies, enforce least-privilege RBAC), applying patches for CVEs (CVE-2019-5736, CVE-2022-22965), and deploying endpoint detection rules that monitor for process injection, anomalous cron jobs, and outbound connections to known mining pools. Tools like Falco or Aqua's open-source Tracee can alert on container escape attempts.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.