Malware.View on attack.mitre.org
Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment.
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
Kinsing has used a script to parse files like |
| T1021.004 SSH |
Kinsing has used SSH for lateral movement. |
| T1053.003 Cron |
Kinsing has used crontab to download and run shell scripts every minute to ensure persistence. |
| T1057 Process Discovery |
Kinsing has used ps to list processes. |
| T1059.004 Unix Shell |
Kinsing has used Unix shell scripts to execute commands in the victim environment. |
| T1071.001 Web Protocols |
Kinsing has communicated with C2 over HTTP. |
| T1078 Valid Accounts |
Kinsing has used valid SSH credentials to access remote hosts. |
| T1083 File and Directory Discovery |
Kinsing has used the find command to search for specific files. |
| T1105 Ingress Tool Transfer |
Kinsing has downloaded additional lateral movement scripts from C2. |
| T1110 Brute Force |
Kinsing has attempted to brute force hosts over SSH. |
| T1133 External Remote Services |
Kinsing was executed in an Ubuntu container deployed via an open Docker daemon API. |
| T1222.002 Linux and Mac Permissions |
Kinsing has used chmod to modify permissions on key files for use. |
| T1496.001 Compute Hijacking |
Kinsing has created and run a Bitcoin cryptocurrency miner. |
| T1552.003 Shell History |
Kinsing has searched |
| T1552.004 Private Keys |
Kinsing has searched for private keys. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.