Sample inventory
Malware sample inventory
Samples captured on the Kinryū Labs honeypot network. Indicators are defanged and hashes are shown in full for detection. Samples are shared with researchers and defenders on request; working exploits are gated and shared by request only. Full analysis for each family lives in its report.
Deep-analysed families
godhive Novel — not on VTC2 live Exposed Docker API
Purpose-built Rust framework. A multi-chain wallet drainer and exchange-withdrawal automation come first, with XMRig mining as the fallback, plus a worm and a command channel layered to survive takedown. The binary carries strings for far more; the report separates what was observed from what is only scaffolded.
- First seen
- July 2026
- Format
- 6.2 MB x86-64 ELF (static musl), Rust
- SHA-256
4194f2337c2b261ed6e1fd0b6d18f0ba75388bdc91a2658eb827a154ed784f36- VirusTotal
- Not on VirusTotal (fully novel)
- Report
- A novel Rust crypto-stealer and miner framework
- Sample
- By request — email [email protected]
rootpacket VT 29/74CVE-2026-31431 Docker API → privileged-container host escape
A cryptojacking toolkit with an intel_uncore_freq_aux LKM rootkit that fakes CPU and memory and rebuilds through DKMS, a UPX-packed XMRig, and a rival-killer. It escalates with getroot, a working exploit for CVE-2026-31431 (an AF_ALG page-cache LPE that also escapes containers to the host).
- First seen
- June 2026
- Format
- ~5 MB toolkit archive (Linux)
- SHA-256
e2d0dab6b29df89d123fe8581047a03ac9b89ae8fa0d1f334b5aefbb93152857- VirusTotal
- 29 engines — trojan.abtrojan/gen2
- Report
- A Linux cryptojacking toolkit that hides in the kernel
- Sample
- GitHub repo
The repo includes getroot, the working CVE-2026-31431 LPE (SHA-256 dda96d8a4bcc39dc7679347a4386bf1024152d2ccc46d333725ad0cda855d952). Detonate only in an isolated, disposable VM with no network path to anything you value.
kworker VT 37/74 Exposed Redis (cron injection)
A Redis cron-injection dropper that kills 80-plus rival miners, uninstalls Alibaba and Tencent cloud-security agents with the vendors’ own tools, trojanises ps/top/pstree to hide its XMRig, backdoors SSH, and worms onward. The stage-2 miner (javae) was never recovered; the C2 did not serve it at fetch time.
- First seen
- June 2026
- Format
- 36 KB POSIX shell script (636 lines)
- SHA-256
7420e819e6cf6d7608e475468ae0160185fe7eed0b5b4129aad3e8dabc776e30- VirusTotal
- 37 engines — trojan.shell, 8220/kworkerds lineage
- Report
- The cryptominer that brings its own uninstaller
- Sample
- By request — email [email protected]
Go DDoS botnet VT 40/74C2 live Jenkins Script Console RCE
A Go-compiled DDoS botnet-for-hire distributed as a multi-architecture dropper suite. Fifteen attack methods, IoT scanner exploits, SSH spreading, and layered persistence, fronting a self-serve, account-gated DDoS-for-hire API.
- First seen
- June–July 2026
- Format
- 6.25 MB PE32+ x86-64 + multi-arch ELF variants (Go)
- SHA-256
6da756970a411dade9db3c921ef4cdade550f317703d0fc12090a15d8c6778d4- VirusTotal
- 40 engines — trojan.gorat/flooder; three distinct builds captured
- Report
- A cross-platform Go DDoS botnet-for-hire
Inside a gaming DDoS-for-hire operation - Sample
- By request — email [email protected]
RedTail Known family Exposed Docker API
An XMRig-based Monero miner that runs fileless via memfd_create, ships an embedded SSH client and a libpcap sniffer, and self-replicates by dropping an SSH key. This is a current, fully captured instance of RedTail delivered through an exposed Docker API.
- First seen
- June 2026
- Format
- ~1.88 MB, multi-arch (x86_64 / i686 / aarch64 / arm7)
- SHA-256
59c29436755b0778e968d49feeae20ed65f5fa5e35f9f7965b8ed93420db91e5- VirusTotal
- Known family (active since late 2023); encrypted config, no embedded wallet
- Report
- Self-propagation through exposed Docker APIs
- Sample
- By request — email [email protected]
Commodity captures
Alongside the deep analyses, the network pulls a steady volume of commodity malware, quarantined and hashed. These are catalogued rather than written up individually.
- Mirai / Gafgyt variants. Multi-arch ELF drops via Telnet brute-force, the dominant volume. 11–14 architecture binaries per campaign wave.
- Jenkins DDoS droppers. Groovy RCE via the Script Console; a bins.sh loader plus arch-specific ELF/PE payloads. Overlaps with the Go DDoS botnet above.
- ESXi OpenSLP payloads. CVE-2021-21974 exploit attempts over UDP/TCP 427; mostly small protocol payloads.
- Malicious Redis modules. Backdoor / loader .so modules loaded via MODULE LOAD.
Requesting a sample
Some families are mirrored to our public GitHub and link there directly; the rest are shared with researchers and defenders by request. Everything here is captured, functional malware, and one repo carries a working local-root exploit, so handle any of it only in an isolated, disposable VM with no network path to anything you value. For a by-request sample, email [email protected] with who you are and what you need it for.