고급 위협 인텔리전스
Kinryū Labs
우리는 우주 시스템의 취약점을 발견하고, 공격자를 실제 환경에서 관찰하기 위해 허니팟 네트워크를 운영하며, 사이버 위협 인텔리전스를 생산하는 연구 그룹입니다. 발견한 것은 영향을 받는 조직에 보고하고, 가능한 것은 준비가 끝나고 공개가 승인되면 발행합니다.
그저 좋아서 합니다.
최신 보고서
전체 보기 →-
Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
-
Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
-
Threat teardown
크로스플랫폼 Go DDoS 대여형 봇넷
Kinryū Labs는 11개 바이너리, 13개 아키텍처의 드로퍼 스위트로 배포되고 여러 날에 걸친 Jenkins Script Console 익스플로잇 캠페인으로 전달된, Go로 컴파일된 DDoS 봇넷의 Windows 빌드 bot.exe를 분석했다. 스테이징 호스트를 정찰한 결과 살아 있고 인증이 걸린 DDoS 대여형 API, Go SSH 명령 채널, 그리고 함께 호스팅된 Mirai 계열 패밀리가 확인되었다. 우리는 이것이 상용 DDoS 대여 작전이라고 높은 확신으로 판단한다.
malware · botnet · ddos · golang · iot · jenkins
kinryu@lab