Thursday, January 30, 2025
HomeComputer SecurityKinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Kinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Published on

SIEM as a Service

Follow Us on Google News

A new malware dubbed Kinsing attacks targeting container environments, the attack particularly targets the misconfigured open Docker Daemon API ports.

The campaign active for months and thousands of containers targeted every day. Researchers from Aquasec observed the attacks.

Researchers believe that “these attacks are directed by actors with sufficient resources and the infrastructure needed to carry out and sustain such attacks”.

Kinsing Malware Attack

The malware exploits the misconfigured Docker API port and runs a malicious Ubuntu container which contains a kinsing malicious malware.

Once exploited it runs a cryptominer and attempts to spread the malware to other containers and hosts. The end goal of the malware attack is to deploy cryptominer.

The attack with the campaign is always the same, but only the IP addressed changes with every attack.

The attempts to connect with C&C servers in Eastern Europe with IP 91[.]215[.]169[.]111 over the port 80 and sends small encrypted messages at regular intervals.

It connects with the server with the IP 193[.]33[.]87[.]219 to download the cryptominer payload and for C&C communication.

The lateral movement handled by a spre.sh shell script that spreads the malware across the container network.

Kinsing Malware

The last stage of the malware is to deploy a cryptominer called kdevtmpfsi, it further communicates with the IP 193[.]33[.]87[.]219 and starts the mining process.

“This attack stands out as yet another example of the growing threat to cloud-native environments. With deployments becoming larger and container use on the rise, attackers are upping their game and mounting more ambitious attacks,” reads Aquasec blog post.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

New RDP Exploit Allows Attackers to Take Over Windows and Browser Sessions

Cybersecurity experts have uncovered a new exploit leveraging the widely used Remote Desktop Protocol...

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that...

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek,...

OPNsense 25.1 Released, What’s New!

The highly anticipated release of OPNsense 25.1 has officially arrived! Nicknamed "Ultimate Unicorn," this...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New Aquabot Malware Actively Exploiting Mitel SIP phones injection vulnerability

Akamai's Security Intelligence and Response Team (SIRT) has uncovered a novel variant of the...

Google Researchers Breakdowns Scatterbrain Behind PoisonPlug Malware

Google’s Threat Intelligence Group (GTIG) in collaboration with Mandiant has revealed critical insights into...

FleshStealer: A new Infostealer Attacking Chrome & Mozilla Users

A newly identified strain of information-stealing malware, FleshStealer, is making headlines in 2025 due...