Tuesday, March 19, 2024

Kinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

A new malware dubbed Kinsing attacks targeting container environments, the attack particularly targets the misconfigured open Docker Daemon API ports.

The campaign active for months and thousands of containers targeted every day. Researchers from Aquasec observed the attacks.

Researchers believe that “these attacks are directed by actors with sufficient resources and the infrastructure needed to carry out and sustain such attacks”.

Kinsing Malware Attack

The malware exploits the misconfigured Docker API port and runs a malicious Ubuntu container which contains a kinsing malicious malware.

Once exploited it runs a cryptominer and attempts to spread the malware to other containers and hosts. The end goal of the malware attack is to deploy cryptominer.

The attack with the campaign is always the same, but only the IP addressed changes with every attack.

The attempts to connect with C&C servers in Eastern Europe with IP 91[.]215[.]169[.]111 over the port 80 and sends small encrypted messages at regular intervals.

It connects with the server with the IP 193[.]33[.]87[.]219 to download the cryptominer payload and for C&C communication.

The lateral movement handled by a spre.sh shell script that spreads the malware across the container network.

Kinsing Malware

The last stage of the malware is to deploy a cryptominer called kdevtmpfsi, it further communicates with the IP 193[.]33[.]87[.]219 and starts the mining process.

“This attack stands out as yet another example of the growing threat to cloud-native environments. With deployments becoming larger and container use on the rise, attackers are upping their game and mounting more ambitious attacks,” reads Aquasec blog post.

Website

Latest articles

CryptoWire Ransomware Attacking Abuses Schedule Task To maintain Persistence

AhnLab security researchers detected a resurgence of CryptoWire, a ransomware strain originally prevalent in...

E-Root Admin Sentenced to 42 Months in Prison for Selling 350,000 Credentials

Tampa, FL – In a significant crackdown on cybercrime, Sandu Boris Diaconu, a 31-year-old...

WhiteSnake Stealer Checks for Mutex & VM Function Before Execution

A new variant of the WhiteSnake Stealer, a formidable malware that has been updated...

Researchers Hack AI Assistants Using ASCII Art

Large language models (LLMs) are vulnerable to attacks, leveraging their inability to recognize prompts...

Microsoft Deprecate 1024-bit RSA Encryption Keys in Windows

Microsoft has announced an important update for Windows users worldwide in a continuous effort...

Beware Of Free wedding Invite WhatsApp Scam That Steal Sensitive Data

The ongoing "free wedding invite" scam is one of several innovative campaigns aimed at...

Hackers Using Weaponized SVG Files in Cyber Attacks

Cybercriminals have repurposed Scalable Vector Graphics (SVG) files to deliver malware, a technique that...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles