home.social

#kinsing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kinsing, aggregated by home.social.

  1. Нежданные гости: F6 проанализировала первые масштабные атаки группы Kinsing на российские компании

    Установить злоумышленников удалось в результате исследования, которое провели аналитики F6 . Весной 2025 года один из клиентов компании зафиксировал попытку кибератаки на свои внешние сервера. Со списком IP-адресов, с которых велась атака, он обратился в департамент киберразведки (Threat Intelligence) компании F6 за атрибуцией.

    habr.com/ru/companies/F6/artic

    #kinsing #криптоджекинг #майнер #уязвимости #cve #киберразведка #threat_intelligence

  2. Нежданные гости: F6 проанализировала первые масштабные атаки группы Kinsing на российские компании

    Установить злоумышленников удалось в результате исследования, которое провели аналитики F6 . Весной 2025 года один из клиентов компании зафиксировал попытку кибератаки на свои внешние сервера. Со списком IP-адресов, с которых велась атака, он обратился в департамент киберразведки (Threat Intelligence) компании F6 за атрибуцией.

    habr.com/ru/companies/F6/artic

    #kinsing #криптоджекинг #майнер #уязвимости #cve #киберразведка #threat_intelligence

  3. Нежданные гости: F6 проанализировала первые масштабные атаки группы Kinsing на российские компании

    Установить злоумышленников удалось в результате исследования, которое провели аналитики F6 . Весной 2025 года один из клиентов компании зафиксировал попытку кибератаки на свои внешние сервера. Со списком IP-адресов, с которых велась атака, он обратился в департамент киберразведки (Threat Intelligence) компании F6 за атрибуцией.

    habr.com/ru/companies/F6/artic

    #kinsing #криптоджекинг #майнер #уязвимости #cve #киберразведка #threat_intelligence

  4. Good day everyone!

    One of my colleagues, Scott Poley, brought this article to my attention during Cyborg Security's "Out of the Woods Podcast" this week and I wanted to share it here as well. This is an article from Aqua Security that covers in-depth the APT group known as #Kinsing. Now, the report is very long and detailed, but what I wanted to highlight was the level of details and the large amount of actionable intel that this report contained. I said it on the podcast and I will repeat it here, this is one of the most complete attacks that I have seen that focuses on the #Linux operating system. I highly recommend reading this when you get the time! Enjoy and Happy Hunting!

    Kinsing Demystified: A Comprehensive Technical Guide
    info.aquasec.com/kinsing-repor

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday Intel 471 #Intel471

  5. Good day everyone!

    One of my colleagues, Scott Poley, brought this article to my attention during Cyborg Security's "Out of the Woods Podcast" this week and I wanted to share it here as well. This is an article from Aqua Security that covers in-depth the APT group known as #Kinsing. Now, the report is very long and detailed, but what I wanted to highlight was the level of details and the large amount of actionable intel that this report contained. I said it on the podcast and I will repeat it here, this is one of the most complete attacks that I have seen that focuses on the #Linux operating system. I highly recommend reading this when you get the time! Enjoy and Happy Hunting!

    Kinsing Demystified: A Comprehensive Technical Guide
    info.aquasec.com/kinsing-repor

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday Intel 471 #Intel471

  6. Good day everyone!

    One of my colleagues, Scott Poley, brought this article to my attention during Cyborg Security's "Out of the Woods Podcast" this week and I wanted to share it here as well. This is an article from Aqua Security that covers in-depth the APT group known as #Kinsing. Now, the report is very long and detailed, but what I wanted to highlight was the level of details and the large amount of actionable intel that this report contained. I said it on the podcast and I will repeat it here, this is one of the most complete attacks that I have seen that focuses on the #Linux operating system. I highly recommend reading this when you get the time! Enjoy and Happy Hunting!

    Kinsing Demystified: A Comprehensive Technical Guide
    info.aquasec.com/kinsing-repor

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday Intel 471 #Intel471

  7. Good day everyone!

    One of my colleagues, Scott Poley, brought this article to my attention during Cyborg Security's "Out of the Woods Podcast" this week and I wanted to share it here as well. This is an article from Aqua Security that covers in-depth the APT group known as #Kinsing. Now, the report is very long and detailed, but what I wanted to highlight was the level of details and the large amount of actionable intel that this report contained. I said it on the podcast and I will repeat it here, this is one of the most complete attacks that I have seen that focuses on the #Linux operating system. I highly recommend reading this when you get the time! Enjoy and Happy Hunting!

    Kinsing Demystified: A Comprehensive Technical Guide
    info.aquasec.com/kinsing-repor

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday Intel 471 #Intel471

  8. Good day everyone!

    One of my colleagues, Scott Poley, brought this article to my attention during Cyborg Security's "Out of the Woods Podcast" this week and I wanted to share it here as well. This is an article from Aqua Security that covers in-depth the APT group known as #Kinsing. Now, the report is very long and detailed, but what I wanted to highlight was the level of details and the large amount of actionable intel that this report contained. I said it on the podcast and I will repeat it here, this is one of the most complete attacks that I have seen that focuses on the #Linux operating system. I highly recommend reading this when you get the time! Enjoy and Happy Hunting!

    Kinsing Demystified: A Comprehensive Technical Guide
    info.aquasec.com/kinsing-repor

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday Intel 471 #Intel471

  9. От падений базы данных до кибератак: история о том, как мы обнаружили взлом

    Статья про расследование простого но интересного киберпреступления. От первых незначительных инцидентов до открытия взлома сервера, мы покажем, как расследовали взлом, копаясь в тысячах строк логов.

    habr.com/ru/articles/810591/

    #Linux #Docker #Kinsing #postgresql #взлом #хакерство

  10. От падений базы данных до кибератак: история о том, как мы обнаружили взлом

    Статья про расследование простого но интересного киберпреступления. От первых незначительных инцидентов до открытия взлома сервера, мы покажем, как расследовали взлом, копаясь в тысячах строк логов.

    habr.com/ru/articles/810591/

    #Linux #Docker #Kinsing #postgresql #взлом #хакерство

  11. Apache ActiveMQ Vulnerability Exploited by Kinsing

    Pulse ID: 657a5ad368a2741d41d801f3
    Pulse Link: otx.alienvault.com/pulse/657a5
    Pulse Author: cryptocti
    Created: 2023-12-14 01:30:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Apache #Vulnerability #ActiveMQ #Kinsing #cryptocti

  12. The follow-up of #Kinsing reveals a rather broad infrastructure, composed as follows:

  13. The follow-up of #Kinsing reveals a rather broad infrastructure, composed as follows:

  14. Our honeypots were deployed on 9 November 2023. The first #Kinsing IS was recorded two days later, on 11 November. We noticed that all these attacks systematically originate from two IP addresses: 109.237.96[.]124 and 78.153.140[.]30.

  15. Our honeypots were deployed on 9 November 2023. The first #Kinsing IS was recorded two days later, on 11 November. We noticed that all these attacks systematically originate from two IP addresses: 109.237.96[.]124 and 78.153.140[.]30.

  16. While the vulnerability has also been exploited to deploy some reverse shell, #Kinsing remains the only significant intrusion set (IS) based on our observation.

  17. While the vulnerability has also been exploited to deploy some reverse shell, #Kinsing remains the only significant intrusion set (IS) based on our observation.

  18. 🚨 Our new report presents a technical analysis of the #ActiveMQ CVE-2023-46604 vulnerability exploited by #Kinsing and an in-depth analysis of this intrusion set, including its infrastructure and #cryptocurrency assets.

    blog.sekoia.io/activemq-cve-20

  19. 🚨 Our new report presents a technical analysis of the #ActiveMQ CVE-2023-46604 vulnerability exploited by #Kinsing and an in-depth analysis of this intrusion set, including its infrastructure and #cryptocurrency assets.

    blog.sekoia.io/activemq-cve-20

  20. CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits

    Trend Vision uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.

    Pulse ID: 655e10007c3ef461cd299611
    Pulse Link: otx.alienvault.com/pulse/655e1
    Pulse Author: AlienVault
    Created: 2023-11-22 14:28:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #CryptoMiner #Linux #Apache #Vulnerability #cryptocurrency #ActiveMQ #Kinsing #AlienVault

  21. > Set up a #Docker based server for the first time.
    > Immediately slapped with the #kinsing miner.

    Quality software, folks.

  22. > Set up a #Docker based server for the first time.
    > Immediately slapped with the #kinsing miner.

    Quality software, folks.