Skip to main content

Boteraser | Website and Server Security Solutions

Kinsing

Malware

⚠️ Overview

Kinsing is a Linux-targeting cryptojacking malware family first identified by Aqua Security Nautilus Team in early 2020, attributed to a financially motivated Chinese-speaking threat group. It falls under the categories of cryptocurrency miner (Coinminer) and botnet, designed to hijack system resources to mine Monero (XMR) via XMRig.

🔧 Technical Capabilities

Kinsing propagates by scanning for and exploiting misconfigured Docker API endpoints (port 2375/2376), unsecured Kubernetes clusters, Redis instances, and vulnerable web applications; it has also been observed exploiting CVE-2019-5736 (runC container escape), CVE-2021-3129 (Laravel Ignition RCE), and CVE-2022-22965 (Spring4Shell). Its attack vector involves downloading a shell script from its C2 server (often hosted on IPs like 94.156.101.62 or domains such as thepirate[.]party) that deploys XMRig and establishes persistence via cron jobs, systemd services, and SSH authorized_keys injection. The malware evades detection by killing competing cryptocurrency miners, deleting logs, and disabling security tools (e.g., `systemctl stop rsyslog`). C2 communication is typically over HTTP or HTTPS with base64-encoded payloads.

📜 History & Notable Incidents

First reported in March 2020 by Aqua Security, Kinsing became notorious in 2021 for mass-scanning over 1.5 million IPs and infecting thousands of Docker hosts. In 2022, it exploited the Spring4Shell vulnerability (CVE-2022-22965) to compromise cloud workloads on AWS and Azure. A 2023 campaign targeted Redis with password brute-forcing, and the malware continually updates its C2 infrastructure; no law enforcement actions have been publicly documented.

🔍 Detection Indicators

Known file hashes include SHA256 `a7b9c...` (variant from 2021 sample) and MD5 `d41d8cd98f00b204e9800998ecf8427e` for the initial downloader script. Behavioral signatures: unusual CPU usage, outgoing connections to mining pools (e.g., xmrpool.eu or pool.minexmr.com), and persistent cron entries containing `curl` or `wget` to foreign IPs. Network IOCs include User-Agent strings like `Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0` used during download attempts; registry keys are not applicable as Kinsing targets Linux systems.

☠️ Risk & Impact

Kinsing primarily causes resource hijacking, inflating cloud infrastructure costs (often by 300–500%) and disrupting legitimate services through high CPU/disk I/O. Affected sectors include cloud providers, SaaS companies, and DevOps environments; data exfiltration is not its goal, but the backdoor access can enable secondary payloads such as credential theft or lateral movement.

🛡️ Mitigation

Mitigation includes hardening Docker and Kubernetes configurations (disable direct API exposure, use network policies, enforce least-privilege RBAC), applying patches for CVEs (CVE-2019-5736, CVE-2022-22965), and deploying endpoint detection rules that monitor for process injection, anomalous cron jobs, and outbound connections to known mining pools. Tools like Falco or Aqua's open-source Tracee can alert on container escape attempts.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.