Saturday, April 19, 2025
HomeComputer SecurityKinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Kinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Published on

SIEM as a Service

Follow Us on Google News

A new malware dubbed Kinsing attacks targeting container environments, the attack particularly targets the misconfigured open Docker Daemon API ports.

The campaign active for months and thousands of containers targeted every day. Researchers from Aquasec observed the attacks.

Researchers believe that “these attacks are directed by actors with sufficient resources and the infrastructure needed to carry out and sustain such attacks”.

- Advertisement - Google News

Kinsing Malware Attack

The malware exploits the misconfigured Docker API port and runs a malicious Ubuntu container which contains a kinsing malicious malware.

Once exploited it runs a cryptominer and attempts to spread the malware to other containers and hosts. The end goal of the malware attack is to deploy cryptominer.

The attack with the campaign is always the same, but only the IP addressed changes with every attack.

The attempts to connect with C&C servers in Eastern Europe with IP 91[.]215[.]169[.]111 over the port 80 and sends small encrypted messages at regular intervals.

It connects with the server with the IP 193[.]33[.]87[.]219 to download the cryptominer payload and for C&C communication.

The lateral movement handled by a spre.sh shell script that spreads the malware across the container network.

Kinsing Malware

The last stage of the malware is to deploy a cryptominer called kdevtmpfsi, it further communicates with the IP 193[.]33[.]87[.]219 and starts the mining process.

“This attack stands out as yet another example of the growing threat to cloud-native environments. With deployments becoming larger and container use on the rise, attackers are upping their game and mounting more ambitious attacks,” reads Aquasec blog post.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

How SMBs Can Improve SOC Maturity With Limited Resources

Small and Medium-sized Businesses (SMBs) have become prime targets for cybercriminals, being three times...

How To Detect Obfuscated Malware That Evades Static Analysis Tools

Obfuscated malware presents one of the most challenging threats in cybersecurity today. As static...

How Security Analysts Detect and Prevent DNS Tunneling Attack In Enterprise Networks

DNS tunneling represents one of the most sophisticated attack vectors targeting enterprise networks today,...

How to Conduct a Cloud Security Assessment

Cloud adoption has transformed organizations' operations but introduces complex security challenges that demand proactive...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

KeyPlug Malware Server Leak Exposes Fortinet Firewall and VPN Exploitation Tools

Cybersecurity researchers have stumbled upon a treasure trove of operational tools and scripts linked...

Researchers Uncover Stealthy Tactics and Techniques of StrelaStealer Malware

Cybersecurity experts have recently shed light on the sophisticated operations of StrelaStealer, also known...

XorDDoS Malware Upgrade Enables Creation of Advanced DDoS Botnets

Cisco Talos has uncovered significant advancements in the XorDDoS malware ecosystem, revealing a multi-layered...