高级威胁情报

Kinryū Labs

我们是一个发现空间系统漏洞、运营蜜罐网络以观察真实环境中的攻击者,并产出网络威胁情报的研究团队。我们将发现的问题报告给受影响的组织,并在内容就绪且获准发布后公开我们能够公开的部分。

纯粹出于热爱。

最新报告

查看全部 →
  • 暴露的 Elasticsearch:勒索擦除经济内幕

    Kinryū Labs 对 17,043 台面向互联网的 Elasticsearch 主机进行了普查,发现一台被擦除、只留着勒索信的空壳是暴露集群最常见的单一状态:共 5,073 台。追踪勒索信中登载的每一个钱包,得到五个行为体、十一笔付款、总收入约 $5,553,并表明归还被删数据的承诺得不到证据支撑。

    elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin

  • Threat teardown

    godhive: A Novel Rust Crypto-Stealer and Miner Framework

    Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.

    malware · cryptojacking · crypto-stealer · rust · docker · worm

  • Threat teardown

    Inside a Gaming DDoS-for-Hire Operation

    Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.

    malware · botnet · ddos · golang · iot · honeypot

kinryu@lab

kinryu@lab: ~/intelligence
$