Skip to content
Malware family CloudLinux

Kinsing

Kinsing is a Linux-focused cryptomining malware family associated with opportunistic exploitation of exposed or vulnerable internet-facing services and subsequent deployment of cryptocurrency miners, commonly for Monero mining.

Profile source: Mallory opens in a new tab

Kinsing

Family profile

Kinsing is a Linux-focused cryptomining malware family associated with opportunistic exploitation of exposed or vulnerable internet-facing services and subsequent deployment of cryptocurrency miners, commonly for Monero mining. It is typically delivered through shell-script-based intrusion chains after remote code execution on misconfigured or unpatched systems, including containerized and cloud-hosted workloads. Reported exploitation paths linked to Kinsing activity include vulnerabilities in products such as JetBrains TeamCity, Apache ActiveMQ, Ivanti Sentry, and PHPUnit, as well as abuse of exposed Docker daemon APIs.

Kinsing is commonly described as a Go-compiled ELF payload that may launch secondary miner-related processes and aggressively monopolize host CPU resources. Its operators use bash scripts to download and execute the malware, remove competing miners, clear traces, and establish persistence. Persistence is frequently achieved through cron job creation or cron file modification. Kinsing-related activity has also included disabling or interfering with security tooling and terminating rival cryptomining processes to retain exclusive access to system resources.

Beyond mining, Kinsing has demonstrated worm-like post-compromise behavior on Linux systems. Documented tradecraft includes SSH brute forcing, use of valid SSH credentials for lateral movement, and parsing of host and SSH trust data to identify additional reachable systems. Kinsing has also been observed using SSH for lateral movement and conducting follow-on reconnaissance in compromised environments. In some intrusion clusters associated with vulnerable edge or application infrastructure, Kinsing infections appeared alongside broader post-exploitation activity such as internal scanning and network discovery.

Kinsing primarily targets Linux servers, containers, and cloud-exposed workloads, especially systems with weak exposure management or exploitable remote services. It is widely tracked as a commodity but effective cryptojacking threat in the Linux ecosystem and is frequently referenced alongside other Linux-focused miner operations such as TeamTNT, Rocke, WatchDog, and Outlaw due to overlapping targeting and anti-competition behavior.

Capabilities

  • Brute Force
  • Defense Evasion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Reconnaissance
  • Scanning

Exploited software

Vulnerabilities linked to Kinsing

8 CVEs

MITRE ATT&CK

Kinsing in ATT&CK

26 distinct techniques

Reporting

Research mentioning Kinsing

Jul 13
Linuxsecurity

Threat Detection Insights on Linux with Signatures and Behavior

If you have a known cryptominer binary—like the ones often deployed by Kinsing or TeamTNT—a YARA rule or a hash match is the most efficient way to flag it.

Jul 2
Scworld

Critical Langflow vulnerability exploited to deploy Monero cryptocurrency miner | brief | SC Media

The malware is designed to terminate competing miners from groups like Kinsing and WatchDog, remove rival wallet data, disable security controls, and establish persistence through cron jobs.

Jun 30
The Hacker News

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

the malware is designed to terminate competing cryptocurrency miner processes associated with Kinsing, WatchDog, Rocke, and Outlaw

Jun 23
Trend Micro Research

From Langflow to Monero: Inside CVE-2026-33017 Cryptominer | Trend Micro (US)

The kill list reveals how deeply the operator knows the Linux cryptomining landscape. Targets include kingsin and kinsin (typo variants of Kinsing, copy-pasted through generations of miner tooling).

Jun 9
Zeropath

Ivanti Sentry CVE-2026-10520: Quick Look at a CVSS 10.0 Unauthenticated Root RCE via OS Command Injection - ZeroPath Blog | ZeroPath

Darktrace documented post exploitation activity that included internal network reconnaissance using Responder for LLMNR poisoning, port scanning with ncat and TxPortMap, and cryptocurrency mining via Kinsing malware and Monero miners.

May 15
Vulncheck

Nine Years and Still Swinging: CVE-2017-9841 Remains One of the Most Actively Targeted Vulnerabilities in Canaries | Blog | VulnCheck

VulnCheck's exploit intelligence data shows CVE-2017-9841 has been leveraged by several botnets including RondoDox, Kinsing, KashmirBlack, Sysrv and Androxgh0st.

Feb 25
Splunk Research

Detection: Linux Possible Append Cronjob Entry on Existing Cronjob File | Splunk Security Content

References https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability

Feb 4
Security Online Info

Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux

"...anti-competition logic to detect and kill rival malware families, such as XMRig miners or the Kinsing botnet..."

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.