Kinsing, also known as H2Miner and Resourceful Wolf, is a financially motivated cybercriminal group active since at least 2019. It specializes in cryptojacking, primarily unauthorized Monero mining, and the creation and expansion of botnets. Its operations predominantly target Linux servers and cloud-native infrastructure, although campaigns against Apache ActiveMQ have also targeted Windows systems. Documented victims include financial, logistics, and telecommunications companies in Russia and vulnerable ActiveMQ servers in South Korea. Kinsing typically conducts automated attacks against internet-exposed, vulnerable, or misconfigured services. Its attack surface includes exposed Docker daemon APIs, Kubernetes environments, Redis, Jenkins, WebLogic, Openfire, and vulnerable containerized applications. Documented exploitation includes PHPUnit CVE-2017-9841, Log4Shell CVE-2021-44228, and Apache ActiveMQ CVE-2023-46604. Following compromise, it deploys shell-script loaders, Kinsing malware, and cryptocurrency miners such as XMRig. It removes competing miners and resource-intensive services, disables host and cloud security controls, and uses obfuscation and rootkits to conceal activity. Persistence includes scheduled cron execution and SSH-based access, while SSH credentials obtained from compromised systems facilitate lateral movement. Alongside its automated mining operations, Kinsing has conducted manual post-exploitation activity in cloud environments. This includes system and account reconnaissance, reverse-shell and web-shell deployment, testing the Looney Tunables privilege-escalation vulnerability CVE-2023-4911, and attempts to retrieve AWS instance metadata and discover cloud credentials. ActiveMQ campaigns have also involved Windows downloaders and the Sharpire .NET backdoor associated with PowerShell Empire, extending its toolkit beyond mining to remote command execution and system administration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
“The initial access was conducted by exploitation of the PHPUnit vulnerability (CVE-2017-9841).” Following exploitation, Kinsing downloaded and executed bc.pl, a Perl script that opened a reverse shell on port 1337.
“These tests were aimed at probing the Looney Tunables vulnerabilities (CVE-2023-4911).” Kinsing downloaded gnu-acme.py, an exploit targeting GNU libc’s ld.so, during an intercepted cloud-environment attack.
이외에도 CVE-2021-44228 Log4j 취약점이나 ActiveMQ의 CVE-2023-46604 취약점 사례가 알려져 있다.
최근 국내 취약한 ActiveMQ 서버를 대상으로 CVE-2023-46604 취약점 공격을 통해 악성코드를 유포하는 사례가 확인되었다.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example threat actor associated with deploying known cryptominer binaries on Linux systems.
Referenced as a rival Linux cryptomining threat actor whose miner artifacts and process names are explicitly targeted for termination by the lambsys operator.
Abuses native Linux utilities, cloud tooling, cron jobs, and SSH persistence in compromised Linux/cloud environments while deploying cryptominers.
Referenced only as another threat actor observed using XMRig.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.