Kinsing Hacker Group Exploits More Flaws to Expand Botnet for Cryptojacking
ID: 4118dff7-2f71-55ab-bac0-4bd7cedcbe6f
STIX ID: report--4118dff7-2f71-55ab-bac0-4bd7cedcbe6f
Feed Name: The Hacker News
Kinsing is a persistent cryptojacking malware family and actor active since at least 2019 that continuously incorporates newly disclosed vulnerabilities and misconfiguration exploitation (e.g., Apache products, Log4j, Docker, Redis, PostgreSQL, WebLogic, SaltStack) to compromise Linux and Windows hosts, disable security controls, deploy rootkits and miners, and operate a global crypto-mining botnet; the report details its three-tier infrastructure (scanners/exploit servers, download servers, C2), categorized scripts and binaries, and observed country-level hosting for payloads and command servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
