Tuesday, October 15, 2024
HomeComputer SecurityKinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Kinsing Malware Attacks Misconfigured Open Docker Daemon API Ports

Published on

Malware protection

A new malware dubbed Kinsing attacks targeting container environments, the attack particularly targets the misconfigured open Docker Daemon API ports.

The campaign active for months and thousands of containers targeted every day. Researchers from Aquasec observed the attacks.

Researchers believe that “these attacks are directed by actors with sufficient resources and the infrastructure needed to carry out and sustain such attacks”.

- Advertisement - SIEM as a Service

Kinsing Malware Attack

The malware exploits the misconfigured Docker API port and runs a malicious Ubuntu container which contains a kinsing malicious malware.

Once exploited it runs a cryptominer and attempts to spread the malware to other containers and hosts. The end goal of the malware attack is to deploy cryptominer.

The attack with the campaign is always the same, but only the IP addressed changes with every attack.

The attempts to connect with C&C servers in Eastern Europe with IP 91[.]215[.]169[.]111 over the port 80 and sends small encrypted messages at regular intervals.

It connects with the server with the IP 193[.]33[.]87[.]219 to download the cryptominer payload and for C&C communication.

The lateral movement handled by a spre.sh shell script that spreads the malware across the container network.

Kinsing Malware

The last stage of the malware is to deploy a cryptominer called kdevtmpfsi, it further communicates with the IP 193[.]33[.]87[.]219 and starts the mining process.

“This attack stands out as yet another example of the growing threat to cloud-native environments. With deployments becoming larger and container use on the rise, attackers are upping their game and mounting more ambitious attacks,” reads Aquasec blog post.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

OilRig Hackers Exploiting Microsoft Exchange Server To Steal Login Details

Earth Simnavaz, an Iranian state-sponsored cyber espionage group, has recently intensified its attacks on...

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...

TrickMo Malware Targets Android Devices to Steal Unlock Patterns and PINs

The recent discovery of the TrickMo Banking Trojan variant by Cleafy has prompted further...

pac4j Java Framework Vulnerable to RCE Attacks

A critical security vulnerability has been discovered in the popular Java framework pac4j. The...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...

TrickMo Malware Targets Android Devices to Steal Unlock Patterns and PINs

The recent discovery of the TrickMo Banking Trojan variant by Cleafy has prompted further...

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

The attackers exploited the EternalBlue vulnerability to gain initial access to the observatory farm,...