logo

Kinsing Malware Exploits Novel Openfire Vulnerability

ID: ce7a36c9-b0d6-57b7-8a7a-5156237f491f

STIX ID: report--ce7a36c9-b0d6-57b7-8a7a-5156237f491f

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2023-08-29

Date Updated: 2026-05-12

...
...

Aqua Nautilus reports an active campaign exploiting Openfire CVE-2023-32315 to perform path traversal into the setup environment, enabling unauthenticated creation of admin users and upload of malicious plugins (cmd.jsp) that deliver Kinsing malware and cryptominers. The analysis includes attack flow, persistence via cronjobs, Shodan-based exposure enumeration (984 vulnerable instances out of ~5,036 reachable servers), honeypot telemetry observing 1,000+ attacks (91% attributed to Kinsing), and detailed IOCs (file SHA256s and attacker/malware host IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.