استخبارات التهديدات المتقدمة
Kinryū Labs
نحن مجموعة بحثية تكتشف الثغرات في أنظمة الفضاء، وتشغّل شبكات مصائد (honeypot) لمراقبة المهاجمين على أرض الواقع، وتُنتج استخبارات التهديدات السيبرانية. نُبلغ المنظمات المتأثرة بما نكتشفه، وننشر ما يمكننا نشره - بمجرد أن يصبح جاهزًا ومُصرّحًا بإصداره.
نفعل هذا حبًّا للمجال.
أحدث التقارير
عرض الكل →-
Elasticsearch المكشوف: داخل اقتصاد المسح مقابل الفدية
أجرت Kinryū Labs تعداداً لـ 17,043 مضيف Elasticsearch مكشوفاً على الإنترنت، ووجدت أن الهيكل الممسوح الذي تُركت فيه مذكرة فدية هو الحالة الأكثر شيوعاً على الإطلاق لعنقود مكشوف: 5,073 منها. وتتبُّع كل محفظة أعلنت عنها المذكرات يعطي خمسة فاعلين، وأحد عشر دفعة، ونحو $5,553 من إجمالي الإيرادات، ويُظهر أن الوعد بإعادة البيانات المحذوفة لا تسنده الأدلة.
elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin
-
Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
-
Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
kinryu@lab