Kinsing, also known as H2Miner, is a Golang-based Linux cryptomining malware family and associated cloud-focused intrusion operation. It primarily deploys XMRig-based Monero mining payloads on compromised servers, containers, and cloud workloads, while also providing remote-access and propagation functionality. Kinsing operators have exploited publicly exposed or misconfigured services and known vulnerabilities, including Apache Log4j, Apache ActiveMQ, SaltStack, Citrix ADC, PHPUnit, Hadoop YARN, and exposed Docker APIs. The malware targets Linux servers, Kubernetes and container environments, Redis and Jenkins deployments, and other internet-facing cloud infrastructure.
Kinsing commonly enumerates processes, scheduled tasks, network connections, and host information; terminates competing miners and selected security processes; and removes competing persistence mechanisms. It establishes persistence through cron jobs and system services, and some activity has loaded a rootkit using the dynamic loader preload mechanism. Kinsing campaigns have conducted service scanning, SSH-based lateral movement, and password-based attacks against accessible services. Observed Kinsing-related tooling can execute commands, use proxying, download and run additional payloads, and conduct network scanning.
Although cryptojacking is its principal objective, Kinsing activity has also included post-exploitation reconnaissance, deployment of web shells and reverse shells, attempts to exploit local privilege-escalation vulnerabilities, and attempts to collect cloud-instance metadata and credentials. These behaviors demonstrate an evolution beyond commodity mining toward broader compromise of cloud-native environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Wiz recommends security teams focus on resources that are still vulnerable to CVE-2021-44228 first, with Log4j version lower than 2.15.0, since it is easier to exploit and is still being heavily exploited in the wild. | “Kinsing — Golang-based malware. It runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim's environment.”
The content notes that actors behind Kinsing have recently exploited CVE-2023-4911 (Looney Tunables) as another high-profile vulnerability. | Active exploitation of Apache ActiveMQ CVE-2023-46604 was used to download and infect Linux systems with Kinsing. Once executed, it downloads additional binaries, establishes cron-based persistence, removes competing miners, and loads a rootkit through /etc/ld.so.preload.
Active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 is being used to download and infect Linux systems with Kinsing malware. The flaw results from OpenWire commands failing to validate Throwable class types during unmarshalling, enabling remote code execution. | Active exploitation of Apache ActiveMQ CVE-2023-46604 was used to download and infect Linux systems with Kinsing. Once executed, it downloads additional binaries, establishes cron-based persistence, removes competing miners, and loads a rootkit through /etc/ld.so.preload.
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | The script kills competing malware and legitimate processes, downloads and executes a cryptominer and KINSING from 78.153.140[.]16, establishes persistence via systemd services and cron jobs and attempts to hide its tracks by clearing the bash history.
In January 2020, the year started off with several malware families conducting campaigns against Citrix Application Delivery Controller (ADC) devices via CVE-2019-19781. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652. | Intezer took the lead on this documentation, demonstrating through an analysis of code similarities that the samples seen in SaltStack exploits were related to the Kinsing RAT. In the execution of the malware, two binaries showed up: a Golang-based RAT and a XMRIG miner. This matches previous Kinsing campaigns.
The Kinsing threat actor has a history of exploiting the PHPUnit vulnerability (CVE-2017-9841)... The initial access was conducted by exploitation of the PHPUnit vulnerability (CVE-2017-9841). | Researchers from Aqua Nautilus have successfully intercepted Kinsing’s experimental incursions into cloud environments... The Kinsing threat actor has a history of exploiting the PHPUnit vulnerability (CVE-2017-9841)... Kinsing downloads and runs the Perl script bc.pl... downloads the script gnu-acme.py, which is actually an exploit of the Looney Tunables vulnerability (CVE-2023-4911)... Subsequently, Kinsing fetches and executes an additional PHP exploit... creating a web shell backdoor allowing further unauthorized access to the server.
In December 2020, Unit 42 researchers observed attempts to exploit CVE-2020-25213, which is a file upload vulnerability in the WordPress File Manager plugin. Successful exploitation of this vulnerability allows an attacker to upload an arbitrary file with arbitrary names and extensions, leading to Remote Code Execution (RCE) on the targeted web server. | This exploit was used by attackers to install webshells, which in turn were used to install Kinsing, malware that runs a malicious cryptominer from the H2miner family.
Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... This vulnerability leads to a path traversal attack, which grants an unauthenticated user access to the Openfire setup environment. This then allows the threat actor to create a new admin user and upload malicious plugins. Eventually the attacker can gain full control over the server. | Aqua Nautilus discovered a new campaign that exploits the Openfire vulnerability (CVE-2023-32315) ... to deploy Kinsing malware and a cryptominer.
NBS team try to bring readers to understand an attack that abusing JetBrains TeamCity vulnerability Authentication Bypass Flaw which led to Remote Code Execution (CVE-2023-42793) as their initial access. The vulnerability was discovered by the PTSWARM team and was abused by various threat actors to spread their malware. | The script includes instructions to download a Linux binary file called 'kinsing' which is a Coinminer malware that are compiled in Golang. Additionally, the execution of the 'kinsing' ELF led to the creation of a process named 'kdevtmpfsi' ELF where the binary was located in the temporary directory Linux (/tmp).
Darktrace observed malicious actors validating exploits for one such critical vulnerability, likely the critical RCE vulnerability, CVE-2023-38035, on Ivanti Sentry servers within multiple customer networks... CVE-2023-38035 is a critical authentication bypass vulnerability affecting the System Manager Portal of Ivanti Sentry systems... an unauthenticated actor with access to the System Manager Portal can achieve Remote Code Execution (RCE) on the underlying Ivanti Sentry system. | In a cryptomining case on another customer’s network, an Ivanti Sentry server was seen making GET requests indicative of Kinsing malware infection.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Most notably, TeamTNT was reported to have copied the code used to detect and remove Alibaba Cloud Security from compromised instances from the Kinsing group.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
This vulnerability allows the creation of a new admin user ... Once the new user is successfully created, it enables the threat actor to undergo a valid authentication process for the Openfire Administration Panel.
“Public exposure to the internet allows malicious actors to scan public addresses and try to send crafted messages to those addresses.” An attack seen in the wild places a JNDI LDAP lookup in the HTTP User-Agent; when logged by vulnerable Log4j, it “will trigger loading and executing code from the URL that the attacker controls.”
establishes persistence by installing it across multiple layers: as a systemd service (if root), as a crontab @reboot job
Kinsing adds a cronjob to download and execute its malicious bootstrap script every minute.
The server then executes the attacker’s shell command ( id , or wget , or anything ) with full Node.js privileges.
Upon successful exploitation, the cryptocurrency miner and malware download the malicious installer, then execute the malicious script using bash.
This will then run the malicious Java code located at http://{malicious website}/{malicious.class} .
establishes persistence by installing it across multiple layers: as a systemd service (if root), as a crontab @reboot job
Kinsing adds a cronjob to download and execute its malicious bootstrap script every minute.
This vulnerability allows the creation of a new admin user ... Once the new user is successfully created, it enables the threat actor to undergo a valid authentication process for the Openfire Administration Panel.
establishes persistence by installing it across multiple layers: as a systemd service (if root), as a crontab @reboot job
Kinsing adds a cronjob to download and execute its malicious bootstrap script every minute.
This vulnerability allows the creation of a new admin user ... Once the new user is successfully created, it enables the threat actor to undergo a valid authentication process for the Openfire Administration Panel.
Kinsing doubles down on its persistence and compromise by loading its rootkit in /etc/ld.so.preload, which completes a full system compromise.
There are a variety of forms of obfuscation being used to prevent detection of scanning or exploitation, including the use of nested strings to invoke the JNDI interface (such as (${${::-j}${::-n}${::-d}${::-I}) ).
Kinsing actively looks for competing cryptocurrency miners ... in processes, crontabs, and active network connections. It then proceeds to kill their processes and network connections.
158 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as the botnet associated with a competing miner that RedTail removes from infected hosts.
Linux-focused cryptocurrency-mining malware that exploits vulnerable web applications and misconfigured container environments for access. It downloads architecture-specific payloads, mines cryptocurrency using host resources, removes competing miners, creates a cron job that re-downloads its bootstrap script every minute, and loads a rootkit via /etc/ld.so.preload for deeper persistence.
Cryptomining malware deployed as a follow-on payload; it establishes persistence, disables defenses, removes competitors, and attempts deeper hooks via /etc/ld.so.preload.
Known Linux cryptominer malware referenced as an example of commodity malware detectable via signatures such as YARA rules or hash matching.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.