Kinsing
Kinsing is a Linux-focused cryptomining malware family associated with opportunistic exploitation of exposed or vulnerable internet-facing services and subsequent deployment of cryptocurrency miners, commonly for Monero mining.
Profile source: Mallory opens in a new tabKinsing
Family profile
Kinsing is a Linux-focused cryptomining malware family associated with opportunistic exploitation of exposed or vulnerable internet-facing services and subsequent deployment of cryptocurrency miners, commonly for Monero mining. It is typically delivered through shell-script-based intrusion chains after remote code execution on misconfigured or unpatched systems, including containerized and cloud-hosted workloads. Reported exploitation paths linked to Kinsing activity include vulnerabilities in products such as JetBrains TeamCity, Apache ActiveMQ, Ivanti Sentry, and PHPUnit, as well as abuse of exposed Docker daemon APIs.
Kinsing is commonly described as a Go-compiled ELF payload that may launch secondary miner-related processes and aggressively monopolize host CPU resources. Its operators use bash scripts to download and execute the malware, remove competing miners, clear traces, and establish persistence. Persistence is frequently achieved through cron job creation or cron file modification. Kinsing-related activity has also included disabling or interfering with security tooling and terminating rival cryptomining processes to retain exclusive access to system resources.
Beyond mining, Kinsing has demonstrated worm-like post-compromise behavior on Linux systems. Documented tradecraft includes SSH brute forcing, use of valid SSH credentials for lateral movement, and parsing of host and SSH trust data to identify additional reachable systems. Kinsing has also been observed using SSH for lateral movement and conducting follow-on reconnaissance in compromised environments. In some intrusion clusters associated with vulnerable edge or application infrastructure, Kinsing infections appeared alongside broader post-exploitation activity such as internal scanning and network discovery.
Kinsing primarily targets Linux servers, containers, and cloud-exposed workloads, especially systems with weak exposure management or exploitable remote services. It is widely tracked as a commodity but effective cryptojacking threat in the Linux ecosystem and is frequently referenced alongside other Linux-focused miner operations such as TeamTNT, Rocke, WatchDog, and Outlaw due to overlapping targeting and anti-competition behavior.
Capabilities
- Brute Force
- Defense Evasion
- Initial Access
- Lateral Movement
- Persistence
- Reconnaissance
- Scanning
Exploited software
Vulnerabilities linked to Kinsing
8 CVEsMITRE ATT&CK
Kinsing in ATT&CK
26 distinct techniquesReporting
Research mentioning Kinsing
Threat Detection Insights on Linux with Signatures and Behavior
If you have a known cryptominer binary—like the ones often deployed by Kinsing or TeamTNT—a YARA rule or a hash match is the most efficient way to flag it.
Critical Langflow vulnerability exploited to deploy Monero cryptocurrency miner | brief | SC Media
The malware is designed to terminate competing miners from groups like Kinsing and WatchDog, remove rival wallet data, disable security controls, and establish persistence through cron jobs.
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
the malware is designed to terminate competing cryptocurrency miner processes associated with Kinsing, WatchDog, Rocke, and Outlaw
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer | Trend Micro (US)
The kill list reveals how deeply the operator knows the Linux cryptomining landscape. Targets include kingsin and kinsin (typo variants of Kinsing, copy-pasted through generations of miner tooling).
Ivanti Sentry CVE-2026-10520: Quick Look at a CVSS 10.0 Unauthenticated Root RCE via OS Command Injection - ZeroPath Blog | ZeroPath
Darktrace documented post exploitation activity that included internal network reconnaissance using Responder for LLMNR poisoning, port scanning with ncat and TxPortMap, and cryptocurrency mining via Kinsing malware and Monero miners.
Nine Years and Still Swinging: CVE-2017-9841 Remains One of the Most Actively Targeted Vulnerabilities in Canaries | Blog | VulnCheck
VulnCheck's exploit intelligence data shows CVE-2017-9841 has been leveraged by several botnets including RondoDox, Kinsing, KashmirBlack, Sysrv and Androxgh0st.
Detection: Linux Possible Append Cronjob Entry on Existing Cronjob File | Splunk Security Content
References https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability
Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux
"...anti-competition logic to detect and kill rival malware families, such as XMRig miners or the Kinsing botnet..."