Kinsing is a financially motivated cryptojacking threat actor focused primarily on Linux and cloud environments. The group is widely associated with opportunistic exploitation of exposed or vulnerable internet-facing services to deploy cryptocurrency miners and supporting malware, and is also tracked under the alias H2Miner. Since first being publicly identified in 2020, Kinsing has remained active through repeated exploitation of known vulnerabilities and misconfigurations affecting web applications, containerized infrastructure, and cloud-hosted services. Kinsing commonly targets Linux servers, containers, and cloud workloads, but activity has also been observed against Windows systems in campaigns exploiting Apache ActiveMQ. The actor is known for abusing exposed Docker environments, weakly secured cloud services, vulnerable public-facing applications, and stolen SSH credentials to gain and expand access. Reported exploitation associated with Kinsing includes CVE-2017-9841, CVE-2021-44228, CVE-2023-46604, and CVE-2023-4911, with operations often aimed at rapid monetization through unauthorized Monero mining. The actor’s tradecraft is characteristic of commodity but effective Linux intrusion activity. Kinsing frequently relies on living-off-the-land techniques, using native utilities and administrative tooling such as shell interpreters, SSH, cron, systemd, curl, wget, and cloud tooling for execution, persistence, and lateral movement. Persistence has repeatedly involved cron jobs, SSH-based access, and system service abuse. In cloud and container environments, Kinsing has been associated with abuse of Docker daemon API misconfigurations, Redis-related access paths, and post-compromise deployment of miners across multiple hosts. Malware and tooling linked to Kinsing include XMRig and custom loaders or stagers, as well as additional post-exploitation frameworks and implants observed in some campaigns. Reporting on exploitation of Apache ActiveMQ has tied Kinsing to deployment of XMRig, Stager, and the Sharpire .NET backdoor, with follow-on use of frameworks such as Cobalt Strike, Meterpreter, and PowerShell Empire. These intrusions indicate that some Kinsing operations go beyond simple miner deployment and can support broader post-exploitation, information theft, and potentially secondary payload delivery. Kinsing is best understood as a persistent, opportunistic cybercriminal operation rather than a nation-state actor. Its targeting patterns are broad and infrastructure-driven, with emphasis on cloud-reliant organizations and exposed Linux systems rather than specific geopolitical victims. The group is frequently discussed alongside other Linux-focused cryptomining actors such as TeamTNT, and its name also appears in rival-miner kill lists used by other commodity Linux malware families, reflecting its longstanding presence in the Linux cryptomining ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example threat actor associated with deploying known cryptominer binaries on Linux systems.
Referenced as a rival Linux cryptomining threat actor whose miner artifacts and process names are explicitly targeted for termination by the lambsys operator.
Abuses native Linux utilities, cloud tooling, cron jobs, and SSH persistence in compromised Linux/cloud environments while deploying cryptominers.
Referenced only as another threat actor observed using XMRig.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.