هوش تهدید پیشرفته

Kinryū Labs

ما یک گروه پژوهشی هستیم که آسیب‌پذیری‌ها را در سامانه‌های فضایی کشف می‌کند، برای رصد مهاجمان در دنیای واقعی شبکه‌های هانی‌پات را به کار می‌گیرد و هوش تهدید سایبری تولید می‌کند. آنچه را می‌یابیم به سازمان‌های آسیب‌دیده گزارش می‌دهیم و آنچه را می‌توانیم منتشر می‌کنیم - به‌محض آنکه آماده و برای انتشار تأیید شده باشد.

این کار را از سرِ عشق انجام می‌دهیم.

تازه‌ترین گزارش‌ها

مشاهده همه →
  • ‏Elasticsearch در معرض دید: درون اقتصادِ پاک‌سازی و باج‌گیری

    ‏Kinryū Labs از 17,043 میزبان Elasticsearchِ رو به اینترنت سرشماری کرد و دریافت که یک پوستهٔ پاک‌شده با یک یادداشت باج‌خواهی درونش، رایج‌ترین وضعیت تک‌گانهٔ یک خوشهٔ در معرض دید است: 5,073 مورد از آن‌ها. ردیابی هر کیف‌پولی که یادداشت‌ها تبلیغ می‌کردند به پنج بازیگر، یازده پرداخت و در مجموع حدود $5,553 درآمد می‌رسد، و نشان می‌دهد که وعدهٔ بازگرداندن داده‌های حذف‌شده از سوی شواهد پشتیبانی نمی‌شود.

    elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin

  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

kinryu@lab

kinryu@lab: ~/intelligence
$