Kinsing Malware Exploits Novel Openfire Vulnerability
ID: ce7a36c9-b0d6-57b7-8a7a-5156237f491f
STIX ID: report--ce7a36c9-b0d6-57b7-8a7a-5156237f491f
Feed Name: Aqua Security Blog
Aqua Nautilus reports an active campaign exploiting Openfire CVE-2023-32315 to perform path traversal into the setup environment, enabling unauthenticated creation of admin users and upload of malicious plugins (cmd.jsp) that deliver Kinsing malware and cryptominers. The analysis includes attack flow, persistence via cronjobs, Shodan-based exposure enumeration (984 vulnerable instances out of ~5,036 reachable servers), honeypot telemetry observing 1,000+ attacks (91% attributed to Kinsing), and detailed IOCs (file SHA256s and attacker/malware host IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
