logo

Kinsing Malware Attacks Targeting Container Environment

ID: a5e794c7-29e9-5cb6-a9a9-9586513de25b

STIX ID: report--a5e794c7-29e9-5cb6-a9a9-9586513de25b

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-04-03

Date Updated: 2026-04-26

...
...

Aqua Security describes an active, persistent campaign exploiting misconfigured Docker Daemon API ports to spawn Ubuntu containers that run a downloaded shell script (d.sh/spre.sh) which installs the Kinsing Go-based malware and a kdevtmpfsi cryptominer. The malware establishes C2 communications, disables defenses, achieves persistence via cron, kills competing malware, and spreads laterally across containers and hosts using harvested SSH credentials and scripted SSH commands; the report includes IPs, URLs, MD5s and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.