보고서
작업이 완료되고 공개가 승인되었을 때 발행하는 보고서입니다. RSS로 구독하세요.
-
Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
-
Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
-
Threat teardown
크로스플랫폼 Go DDoS 대여형 봇넷
Kinryū Labs는 11개 바이너리, 13개 아키텍처의 드로퍼 스위트로 배포되고 여러 날에 걸친 Jenkins Script Console 익스플로잇 캠페인으로 전달된, Go로 컴파일된 DDoS 봇넷의 Windows 빌드 bot.exe를 분석했다. 스테이징 호스트를 정찰한 결과 살아 있고 인증이 걸린 DDoS 대여형 API, Go SSH 명령 채널, 그리고 함께 호스팅된 Mirai 계열 패밀리가 확인되었다. 우리는 이것이 상용 DDoS 대여 작전이라고 높은 확신으로 판단한다.
malware · botnet · ddos · golang · iot · jenkins
-
Threat teardown
Kworker: 자체 제거 도구를 들고 오는 암호화폐 채굴기
Kinryū Labs는 8220 계열의 크립토재커가 열려 있고 비밀번호 없는 Redis 포트를 약 5초 만에 root 셸로 바꾸는 것을 포착했다. kworker라는 636줄짜리 셸 스크립트 드로퍼는 Alibaba와 Tencent의 클라우드 보안 에이전트를 벤더 자신의 도구로 제거하고, 200줄을 들여 경쟁 채굴기를 죽이며, SSH에 백도어를 심고, XMRig 모네로 채굴기를 가짜 ps·top·pstree 뒤에 숨기고, 더 멀리 퍼지려 시도한다.
malware · cryptomining · redis · linux · honeypot · monero
-
Coordinated disclosure native.org
열린 Kibana가 노출시킨 native.org의 트레이딩 스택
위협 인텔리전스 연구 중 Kinryū Labs는 native.org 소유의 인증 없는 Kibana를 발견했다. 이 인스턴스는 회사의 전체 트레이딩 스택 아키텍처를 드러냈고, 활성 API 키를 평문으로 로그에 기록하고 있었다. native.org는 접근을 제한하고 키를 교체했다.
coordinated-disclosure · kibana · elasticsearch · data-exposure · defi · cloud-misconfiguration
-
Threat teardown CVE-2026-31431
Rootpacket: 커널에 숨는 Linux 크립토재킹 툴킷
Kinryū Labs는 Rootpacket을 분석했다. 이 Linux 크립토재킹 툴킷은 CPU와 메모리 사용량을 위조하는 커널 루트킷을 싣고, CVE-2026-31431(컨테이너에서 호스트로도 탈출하는 AF_ALG 페이지 캐시 결함)을 통해 root로 상승하며, Intel 드라이버로 위장하고, 경쟁 채굴기가 들어오는 데 쓰는 바로 그 노출된 서비스를 비활성화한다.
malware · cryptomining · rootkit · linux · kernel · monero
-
Threat teardown
RedTail 캠페인의 내부: 노출된 Docker API를 통한 자기 전파
Kinryū Labs 허니팟이 인증 없는 Docker Engine API와 떨군 SSH 키를 통해 퍼지는 RedTail 채굴기를 포착했다. 이 글은 로더, 경쟁자 제거 스크립트, 채굴기, 그리고 살아 있는 지표를 갖춘, 현재 시점의 완전히 포착된 사례를 기록한다.
malware · cryptomining · redtail · docker · linux · honeypot