고급 위협 인텔리전스

Kinryū Labs

우리는 우주 시스템의 취약점을 발견하고, 공격자를 실제 환경에서 관찰하기 위해 허니팟 네트워크를 운영하며, 사이버 위협 인텔리전스를 생산하는 연구 그룹입니다. 발견한 것은 영향을 받는 조직에 보고하고, 가능한 것은 준비가 끝나고 공개가 승인되면 발행합니다.

그저 좋아서 합니다.

최신 보고서

전체 보기 →
  • 노출된 Elasticsearch: 랜섬-와이프 경제의 내부

    Kinryū Labs는 인터넷에 노출된 Elasticsearch 호스트 17,043개를 전수 조사했고, 몸값 요구문이 남겨진 채 데이터가 지워진 껍데기가 노출된 클러스터의 가장 흔한 단일 상태임을 확인했다. 그런 호스트가 5,073개다. 요구문이 광고한 모든 지갑을 추적한 결과 행위자 다섯, 결제 열한 건, 총수익 약 $5,553이 드러났으며, 삭제된 데이터를 돌려주겠다는 약속이 증거로 뒷받침되지 않음을 보여준다.

    elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin

  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

kinryu@lab

kinryu@lab: ~/intelligence
$