レポート
作業が完了し公開が許可された時点で公表する解説記事です。RSS で購読できます。
-
Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
-
Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
-
Threat teardown
クロスプラットフォームな Go 製 DDoS 貸出ボットネット
Kinryū Labs は、11 個のバイナリ・13 アーキテクチャの投下器スイートとして配布され、複数日にわたる Jenkins Script Console 悪用キャンペーンで送り込まれた、Go でコンパイルされた DDoS ボットネットの Windows ビルド bot.exe を分析した。ステージングホストの偵察により、稼働中で認証を要する DDoS 貸出 API、Go 製の SSH コマンドチャネル、そして同居する Mirai 系統の一族が判明した。我々はこれを商用の DDoS 貸出オペレーションであると高い確度で評価する。
malware · botnet · ddos · golang · iot · jenkins
-
Threat teardown
Kworker:自前のアンインストーラーを持参するマイナー
Kinryū Labs は、8220 系統のマイナーが、開放され、パスワードもない Redis ポートを、わずか五秒ほどで root シェルに変える様子を捕捉した。この投下器は kworker という名の 636 行の shell スクリプトで、アリババとテンセントのクラウドセキュリティ agent をベンダー自身のツールでアンインストールし、200 行を費やして競合マイナーを駆除し、SSH にバックドアを仕込み、XMRig モネロ・マイナーを偽の ps・top・pstree の背後に隠し、さらにワームとして広がろうとする。
malware · cryptomining · redis · linux · honeypot · monero
-
Coordinated disclosure native.org
公開された Kibana が native.org の取引スタックを露呈させた
脅威インテリジェンス調査の過程で、Kinryū Labs は native.org に属する認証なしの Kibana を発見した。それは取引スタックの全体アーキテクチャを露呈させ、有効な API キーを平文でログに記録していた。native.org はアクセスを制限し、鍵をローテーションした。
coordinated-disclosure · kibana · elasticsearch · data-exposure · defi · cloud-misconfiguration
-
Threat teardown CVE-2026-31431
Rootpacket:カーネルに潜む Linux クリプトジャッキング・ツールキット
Kinryū Labs は Rootpacket を分析した。これは Linux 向けのクリプトジャッキング・ツールキットで、CPU とメモリの使用率を偽るカーネル・ルートキットを携え、CVE-2026-31431(コンテナからホストへも逃げ出す AF_ALG ページキャッシュの欠陥)で root へ昇格し、Intel ドライバになりすまし、競合マイナーが侵入に使うのと同じ露出サービスを無効化する。
malware · cryptomining · rootkit · linux · kernel · monero
-
Threat teardown
RedTail キャンペーンの内側:露出した Docker API を通じた自己増殖
Kinryū Labs のハニーポットが、認証なしの Docker Engine API と投下された SSH 鍵を通じて広がる RedTail マイナーを捕捉した。本稿は、ローダー、競合除去スクリプト、マイナー本体、そしてリアルタイムの指標を含む、現行かつ完全に捕獲した一例を記録する。
malware · cryptomining · redtail · docker · linux · honeypot