s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.kinsing

📛 Threat Title

Malware family: Kinsing

Category: Kinsing First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.kinsing`. Printable name: Kinsing. Aliases: h2miner.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.kinsing VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kinsing

IOC database

Type
domain
Value
elf.kinsing
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.kinsing

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.kinsing

References (1)

Remediations (10)

  • web:attack.mitre.org

    Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment. [1] [2] [3]

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Kinsing malware family including references, samples and yara signatures.

  • web:medium.com

    Mitigating the Kinsing Threat: Protecting Your System from Cryptojacking Software Updates: Patching your operating system and applications with the latest security updates is crucial.

  • web:reddogsecurity.substack.com

    From NSPPS to Kinsing - An Evolution in Profit-Driven Malware The story of Kinsing doesn't begin in 2019. Researchers have traced its lineage back to an earlier Go-based malware family known as NSPPS, a remote access Trojan (RAT) that shared the same RC4 encryption keys and many of the same function names. By 2020, the evolution was clear.

  • web:thehackernews.com

    Kinsing cryptojacking group evolves again, targeting new vulnerabilities to expand its botnet.

  • web:www.cyberark.com

    While analyzing a few Kinsing samples, we were surprised to find some artifacts related to another malware family called NSPPS. At first, we came up with several ideas that might explain those findings- maybe the common parts are open source tools that are used by both families, or perhaps one group mimics the other.

  • web:www.huntress.com

    Technical analysis of Kinsing malware Kinsing incorporates robust infection mechanisms to achieve persistence and evade detection. After initial access, it disables security defenses, downloads cryptomining software, and establishes persistence through cron jobs or system services.

  • web:www.reddit.com

    In this write-up, we methodically and thoroughly analyzed every aspect of Kinsing . We established that this is the work of a single attacker with an impressive pipeline by tapping into the download server, analyzing the attack scripts, C2 malware , and rootkits.

  • web:www.tenable.com

    The Kinsing malware uses different locations to stay undetected and hides itself as a system file. We've found it in four locations, presumably for persistence purposes. Interestingly, three of these locations are manual files, or 'man' pages, where malware is rarely found.

  • web:www.vulncheck.com

    Canary Intelligence linked exploitation of CVE-2023-46604, CVE-2023-38646, and CVE-2025-55182 to the same Kinsing infrastructure, including a shared staging host and attacker IP first seen in the canary network on March 12, 2026. The research shows how an older malware family is still adapting by adding new exploit paths while continuing to rely on established infrastructure.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.