Advanced threat intelligence

Kinryū Labs

We're a research group that finds vulnerabilities in space systems, runs honeypot networks to watch attackers in the wild, and produces cyber threat intelligence. We report what we find to the organisations affected, and publish what we can - once it's ready and cleared for release.

Doing it for the love of the game.

Latest reports

View all →
  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

  • Threat teardown

    A Cross-Platform Go DDoS Botnet-for-Hire

    Kinryū Labs analysed bot.exe, the Windows build of a Go-compiled DDoS botnet distributed as an 11-binary, 13-architecture dropper suite and delivered through a multi-day Jenkins Script Console exploitation campaign. Reconnaissance of the staging host identified a live, authenticated DDoS-for-hire API, a Go SSH command channel, and a co-hosted Mirai-lineage family. We assess with high confidence that this is a commercial DDoS-for-hire operation.

    malware · botnet · ddos · golang · iot · jenkins

kinryu@lab

kinryu@lab: ~/intelligence
$