Kinsing Malware Attacks Targeting Container Environment
ID: a5e794c7-29e9-5cb6-a9a9-9586513de25b
STIX ID: report--a5e794c7-29e9-5cb6-a9a9-9586513de25b
Feed Name: Aqua Security Blog
Aqua Security describes an active, persistent campaign exploiting misconfigured Docker Daemon API ports to spawn Ubuntu containers that run a downloaded shell script (d.sh/spre.sh) which installs the Kinsing Go-based malware and a kdevtmpfsi cryptominer. The malware establishes C2 communications, disables defenses, achieves persistence via cron, kills competing malware, and spreads laterally across containers and hosts using harvested SSH credentials and scripted SSH commands; the report includes IPs, URLs, MD5s and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
