高级威胁情报

Kinryū Labs

我们是一个发现空间系统漏洞、运营蜜罐网络以观察真实环境中的攻击者,并产出网络威胁情报的研究团队。我们将发现的问题报告给受影响的组织,并在内容就绪且获准发布后公开我们能够公开的部分。

纯粹出于热爱。

最新报告

查看全部 →
  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

  • Threat teardown

    一个跨平台的 Go DDoS 出租型僵尸网络

    Kinryū Labs 分析了 bot.exe——一个 Go 编译的 DDoS 僵尸网络的 Windows 构建版本,它以一套包含 11 个二进制、覆盖 13 种架构的投放器套件形式分发,并通过一场为期数天的 Jenkins Script Console 利用行动投递。对暂存主机的侦察发现了一个在线的、需认证的 DDoS 出租 API、一个 Go 编写的 SSH 命令通道,以及一个同宿的 Mirai 血统家族。我们以高置信度评估,这是一场商业化的 DDoS 出租行动。

    malware · botnet · ddos · golang · iot · jenkins

kinryu@lab

kinryu@lab: ~/intelligence
$