高度な脅威インテリジェンス

Kinryū Labs

私たちは、宇宙システムの脆弱性を発見し、実環境で攻撃者を観察するためにハニーポットネットワークを運用し、サイバー脅威インテリジェンスを生み出す研究グループです。見つけたものは影響を受ける組織に報告し、公開できるものは準備が整い公開が許可された段階で公表します。

ただ、好きでやっている。

最新のレポート

すべて表示 →
  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

  • Threat teardown

    クロスプラットフォームな Go 製 DDoS 貸出ボットネット

    Kinryū Labs は、11 個のバイナリ・13 アーキテクチャの投下器スイートとして配布され、複数日にわたる Jenkins Script Console 悪用キャンペーンで送り込まれた、Go でコンパイルされた DDoS ボットネットの Windows ビルド bot.exe を分析した。ステージングホストの偵察により、稼働中で認証を要する DDoS 貸出 API、Go 製の SSH コマンドチャネル、そして同居する Mirai 系統の一族が判明した。我々はこれを商用の DDoS 貸出オペレーションであると高い確度で評価する。

    malware · botnet · ddos · golang · iot · jenkins

kinryu@lab

kinryu@lab: ~/intelligence
$