logo

Kinsing Hacker Group Exploits More Flaws to Expand Botnet for Cryptojacking

ID: 4118dff7-2f71-55ab-bac0-4bd7cedcbe6f

STIX ID: report--4118dff7-2f71-55ab-bac0-4bd7cedcbe6f

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Kinsing is a persistent cryptojacking malware family and actor active since at least 2019 that continuously incorporates newly disclosed vulnerabilities and misconfiguration exploitation (e.g., Apache products, Log4j, Docker, Redis, PostgreSQL, WebLogic, SaltStack) to compromise Linux and Windows hosts, disable security controls, deploy rootkits and miners, and operate a global crypto-mining botnet; the report details its three-tier infrastructure (scanners/exploit servers, download servers, C2), categorized scripts and binaries, and observed country-level hosting for payloads and command servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.