Kinsing

MITRE ATT&CK: S0599 View on attack.mitre.org

Aliases: h2miner, Kinsing

First seen
2019-12-01 00:00:00
Malware type
cryptominer, worm
Family
Malware family
Operating systems
containers, linux
Related IoCs
131 (50 malicious)
Last IoC activity
2026-09-01 20:01:49
Profile updated
2026-07-07 12:59:01

Targeted industries: technology-and-telecommunications transportation-and-logistics energy-and-utilities

Context

Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment.

Recent IoC activity

50 malicious indicators in Maltiverse are attributed to Kinsing (S0599). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 119.29.247.220 2026-09-02 8
IP address 123.207.35.85 2026-09-01 7
IP address 221.130.29.85 2026-09-01 7
IP address 135.136.39.69 2026-09-01 4
file sample kinsing_aarch64 2026-08-21 2
file sample d.sh 2026-08-18 1
file sample 2026-04-07_5a474b4c2fadf813e32cc4e60bf56532_deimos_glassworm_kinsing_poet-rat... 2026-08-15 1
file sample xmss 2026-08-11 2
IP address 175.107.0.134 2026-08-09 6
file sample sc.sh 2026-08-08 3
file sample pg.sh 2026-08-06 1
file sample a.sh 2026-08-06 1
file sample i.sh 2026-08-03 2
file sample mt.sh 2026-07-23 2
file sample exp_f32b209d.so 2026-07-18 2
file sample ph.sh 2026-07-15 2
URL http://s.na-cs.com/t.sh 2026-07-13 1
URL http://s.na-cs.com/b2f628/b.sh 2026-07-13 1
file sample init.sh 2026-07-09 2
file sample newinit.sh 2026-07-07 2

Detection coverage

  • 4 YARA rules
  • 286 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Deploy Container (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Unix Shell (attack-pattern)
  • Private Keys (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Shell History (attack-pattern)
  • Brute Force (attack-pattern)
  • SSH (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • External Remote Services (attack-pattern)
  • Cron (attack-pattern)
  • Container Administration Command (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Process Discovery (attack-pattern)
  • Compute Hijacking (attack-pattern)

Exploited vulnerabilities

  • CVE-2020-25213 (vulnerability)
  • CVE-2021-44228 (vulnerability)
  • CVE-2022-26134 (vulnerability)

Detection rules

  • ARKBIRD_SOLG_Loader_JAVA_Kinsing_Aug_2020_Variant_B_1 (yara-rule)
  • DITEKSHEN_MALWARE_Linux_Kinsing (yara-rule)
  • SEKOIA_Bot_Lin_Kinsing_Strings (yara-rule)
  • SIGNATURE_BASE_Crime_H2Miner_Kinsing (yara-rule)

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • Trend Micro — Analysis Of Kinsing Malwares Use Of Rootkit (report)
  • blog.aquasec.com — Threat Alert Kinsing Malware Container Vulnerability (report)
  • sysdig.com — Zoom Into Kinsing Kdevtmpfsi (report)
  • Palo Alto Unit 42 — Moneylibra (report)
  • twitter.com — 1535417776290111489 (report)
  • vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
  • lacework.com — Kinsing Dark Iot Botnet Among Threats Targeting Cve 2022 26134 (report)
  • aquasec.com — Aqua Cndr Stop Dreambus Botnet Attack (report)
  • ibm.com — Wmdzowk6 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Kinsing (report)
  • bleepingcomputer.com — Log4Shell Exploits Now Used Mostly For Ddos Botnets Cryptominers (report)
  • Trend Micro — A Post Exploitation Look At Coinminers Abusing Weblogic Vulnerab (report)
  • redcanary.com — Kinsing Malware Citrix Saltstack (report)
  • Trend Micro — Threat Actors Exploit Misconfigured Apache Hadoop Yarn (report)
  • aquasec.com — Kinsing Malware Exploits Novel Openfire Vulnerability (report)
  • twitter.com — 1259818964848386048 (report)
  • zscaler.com — Threatlabz Analysis Log4Shell Cve 2021 44228 Exploit Attempts (report)
  • medium.com — Logs Of Log4Shell Cve 2021 44228 Log4J Is Ubiquitous En 809064312039 (report)
  • 1665891.fs1.hubspotusercontent-na1.net — Aquasecurity Kinsing Demystified Technical Guide (report)
  • cyberark.com — Kinsing The Malware With Two Faces (report)
  • Palo Alto Unit 42 — Cve 2020 25213 (report)
  • alibabacloud.com — New Outbreak Of H2Miner Worms Exploiting Redis Rce Detected 595743 (report)
  • aquasec.com — Loony Tunables Vulnerability Exploited By Kinsing (report)
  • blog.aquasec.com — Kinsing Malware Exploits Novel Openfire Vulnerability (report)

External references