דוחות
דוחות מתפרסמים כשהעבודה הושלמה ואושרה לפרסום. הרשמה דרך RSS.
-
Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
-
Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
-
Threat teardown
בוטנט DDoS-להשכרה חוצה-פלטפורמות בשפת Go
Kinryū Labs ניתחה את bot.exe, גרסת ה-Windows של בוטנט DDoS שהודר בשפת Go ומופץ כערכת דרופר של 11 קבצים בינאריים ו-13 ארכיטקטורות, ונמסר דרך קמפיין ניצול רב-ימים של Jenkins Script Console. סקירה של מארח ההיערכות זיהתה API חי ומאומת של DDoS-להשכרה, ערוץ פקודה SSH בשפת Go, ומשפחה משושלת Mirai המתארחת לצדם. אנו מעריכים בביטחון גבוה שמדובר במבצע DDoS-להשכרה מסחרי.
malware · botnet · ddos · golang · iot · jenkins
-
Threat teardown
Kworker: כורה המטבעות שמביא איתו את מסיר ההתקנה שלו
Kinryū Labs תפסה כורה מטבעות זדוני משושלת 8220 הופך יציאת Redis פתוחה וללא סיסמה לקליפת root בכחמש שניות. הדרופר, סקריפט מעטפת בן 636 שורות בשם kworker, מסיר את סוכני אבטחת הענן של Alibaba ו-Tencent בעזרת הכלים של היצרנים עצמם, מבזבז 200 שורות על הריגת כורים מתחרים, שותל דלת אחורית ב-SSH, מסתיר כורה מונרו XMRig מאחורי ps, top ו-pstree מזויפים, ומנסה להתפשט הלאה.
malware · cryptomining · redis · linux · honeypot · monero
-
Coordinated disclosure native.org
קיבانה פתוחה חשפה את מחסנית המסחר של native.org
במהלך מחקר מודיעין איומים, Kinryū Labs מצאה מופע Kibana ללא אימות השייך ל-native.org שחשף את כל ארכיטקטורת מחסנית המסחר שלה ותיעד מפתחות API פעילים כטקסט גלוי. native.org הגבילה את הגישה והחליפה את המפתחות.
coordinated-disclosure · kibana · elasticsearch · data-exposure · defi · cloud-misconfiguration
-
Threat teardown CVE-2026-31431
Rootpacket: ערכת כריית מטבעות ל-Linux שמתחבאת בליבה
Kinryū Labs ניתחה את Rootpacket, ערכת כריית מטבעות ל-Linux הנושאת רוטקיט ברמת הליבה לזיוף ניצול המעבד והזיכרון, מסלימה ל-root דרך CVE-2026-31431 (פגם במטמון העמודים של AF_ALG שגם בורח מקונטיינרים אל המארח), מתחזה למנהל התקן של Intel, ומשביתה את אותם שירותים חשופים שדרכם נכנסים כורים מתחרים.
malware · cryptomining · rootkit · linux · kernel · monero
-
Threat teardown
בתוך קמפיין RedTail: התפשטות עצמית דרך ממשקי Docker API חשופים
מלכודות הדבש של Kinryū Labs תפסו את כורה המטבעות RedTail מתפשט דרך ממשקי Docker Engine API ללא אימות ומפתחות SSH מושלכים. כתבה זו מתעדת מופע עכשווי שנלכד במלואו, עם המטעין, סקריפט הסרת המתחרים, הכורה, ומחוונים חיים.
malware · cryptomining · redtail · docker · linux · honeypot