Full Report
Researchers observed recent activities surrounding the Kinsing malware, which primarily targets Linux-based cloud infrastructure. Kinsing exploits various vulnerabilities to gain unauthorized access and deploys backdoors and cryptominers. Recent findings show that Kinsing also...
Analysis Summary
# Tool/Technique: Kinsing Malware
## Overview
Kinsing is a prevalent malware family primarily targeting Linux-based cloud infrastructure. Its main objectives are to gain unauthorized access via vulnerability exploitation, deploy backdoors for persistence, and utilize compromised resources for cryptocurrency mining (cryptojacking). Recent activity shows it specifically targeting Apache Tomcat servers.
## Technical Details
- Type: Malware family
- Platform: Linux, Cloud infrastructure (including containers)
- Capabilities: Vulnerability exploitation, deployment of backdoors, cryptomining.
- First Seen: Not explicitly stated in the context, but described as "recent activities."
## MITRE ATT&CK Mapping
*Note: Specific TTPs are inferred based on the description of activities.*
| Tactic | Technique ID & Name | Sub-technique |
| :--- | :--- | :--- |
| Initial Access | T1190 - Exploit Public-Facing Application | |
| Execution | T1059.004 - Command and Scripting Interpreter: Unix Shell | |
| Persistence | T1543.003 - Create or Modify System Process: Scheduled Task/Job | (Inferred for persistence methods) |
| Defense Evasion | T1036 - Masquerading | T1036.005 - Match Legitimate Name or Location |
## Functionality
### Core Capabilities
- **Vulnerability Exploitation:** Gains initial access by exploiting weaknesses in cloud servers and containers.
- **Deployment of Backdoors:** Establishes persistence mechanisms on compromised systems.
- **Cryptomining:** Deploys cryptomining payloads (e.g., XMRig) to utilize victim CPU resources for generating cryptocurrency.
### Advanced Features
- **Targeted Applications:** Specifically observed targeting Apache Tomcat vulnerabilities in recent campaigns.
- **File System Evasion:** Employs innovative techniques to hide payloads in unconventional filesystem locations to evade detection:
* `/var/cache/man/cs/cat1/` (mimicking user commands)
* `/var/cache/man/cs/cat3/` (mimicking library functions)
* `/var/lib/gssproxy/rcache/`
## Indicators of Compromise
- File Hashes: [Not provided in context]
- File Names: [Not provided in context, but likely generic or obfuscated names associated with payloads like XMRig]
- Registry Keys: [Not applicable for primary Linux target]
- Network Indicators: [IPs and Domains not provided in context, but would be associated with C2 or XMRig mining pools]
- Behavioral Indicators:
- Executing processes related to cryptocurrency mining (XMRig).
- File writes/creation in unusual system cache or resource directories (`/var/cache/man/`, `/var/lib/gssproxy/`).
## Associated Threat Actors
- Kinsing Operator (Self-named within the context)
## Detection Methods
- Signature-based detection: Signatures targeting known Kinsing payloads or XMRig binaries.
- Behavioral detection: Monitoring for unusual process execution patterns or resource utilization indicative of cryptomining.
- YARA rules: Rules targeting unique strings or entropy patterns within the hidden files.
## Mitigation Strategies
- **Patch Management:** Promptly patch public-facing applications and containers, especially focusing on known exploited vulnerabilities.
- **Least Privilege:** Implement strong access controls on cloud infrastructure components, particularly for services like Apache Tomcat.
- **Filesystem Monitoring:** Implement real-time monitoring for unexpected file creation or modification in system directories, particularly cache or library paths (`/var/cache/man`, `/var/lib/`).
- **Resource Monitoring:** Establish baselines for CPU utilization on cloud servers, alerting on sustained high usage that might indicate cryptomining activity.
## Related Tools/Techniques
- **XMRig:** The observed cryptominer tool used by the campaign.
- Other Linux backdoors and cryptojacking malware families targeting cloud environments.