TF-MAL-elf.kinsing
📛 Threat Title
Malware family: Kinsing
Description
ThreatFox malware family `elf.kinsing`. Printable name: Kinsing. Aliases: h2miner.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.kinsing
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kinsing
IOC database
- Type
- domain
- Value
elf.kinsing- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.kinsing
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kinsing
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment. [1] [2] [3]
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Kinsing malware family including references, samples and yara signatures.
-
web:medium.com
Mitigating the Kinsing Threat: Protecting Your System from Cryptojacking Software Updates: Patching your operating system and applications with the latest security updates is crucial.
-
web:reddogsecurity.substack.com
From NSPPS to Kinsing - An Evolution in Profit-Driven Malware The story of Kinsing doesn't begin in 2019. Researchers have traced its lineage back to an earlier Go-based malware family known as NSPPS, a remote access Trojan (RAT) that shared the same RC4 encryption keys and many of the same function names. By 2020, the evolution was clear.
-
web:thehackernews.com
Kinsing cryptojacking group evolves again, targeting new vulnerabilities to expand its botnet.
-
web:www.cyberark.com
While analyzing a few Kinsing samples, we were surprised to find some artifacts related to another malware family called NSPPS. At first, we came up with several ideas that might explain those findings- maybe the common parts are open source tools that are used by both families, or perhaps one group mimics the other.
-
web:www.huntress.com
Technical analysis of Kinsing malware Kinsing incorporates robust infection mechanisms to achieve persistence and evade detection. After initial access, it disables security defenses, downloads cryptomining software, and establishes persistence through cron jobs or system services.
-
web:www.reddit.com
In this write-up, we methodically and thoroughly analyzed every aspect of Kinsing . We established that this is the work of a single attacker with an impressive pipeline by tapping into the download server, analyzing the attack scripts, C2 malware , and rootkits.
-
web:www.tenable.com
The Kinsing malware uses different locations to stay undetected and hides itself as a system file. We've found it in four locations, presumably for persistence purposes. Interestingly, three of these locations are manual files, or 'man' pages, where malware is rarely found.
-
web:www.vulncheck.com
Canary Intelligence linked exploitation of CVE-2023-46604, CVE-2023-38646, and CVE-2025-55182 to the same Kinsing infrastructure, including a shared staging host and attacker IP first seen in the canary network on March 12, 2026. The research shows how an older malware family is still adapting by adding new exploit paths while continuing to rely on established infrastructure.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.