August 23, 2026 keyHunter: An LLM-Proxy Key Operation That Leaked Its Own Toolkit A Chinese-speaking operator sweeps FOFA for exposed AI proxy panels, verifies them with unit-tested code built to recognise honeypots, and exports the API keys. Their agent executed a Kinryū Labs decoy's tool calls on its own host and returned 283 file paths, the scan yields, the WeChat chat log, and a results directory of exploit files named for six 2026 CVEs, a New-API Stripe-webhook bypass among them. threat-actor · litellm · agentic-ai · credential-theft · china-nexus
keyHunter: An LLM-Proxy Key Operation That Leaked Its Own Toolkit
A Chinese-speaking operator sweeps FOFA for exposed AI proxy panels, verifies them with unit-tested code built to recognise honeypots, and exports the API keys. Their agent executed a Kinryū Labs decoy's tool calls on its own host and returned 283 file paths, the scan yields, the WeChat chat log, and a results directory of exploit files named for six 2026 CVEs, a New-API Stripe-webhook bypass among them.
threat-actor · litellm · agentic-ai · credential-theft · china-nexus
August 8, 2026 Exposed Elasticsearch: Inside the Ransom-Wipe Economy Kinryū Labs censused 17,043 internet-facing Elasticsearch hosts and found that a wiped husk with a ransom note in it is the single most common state of an exposed cluster: 5,073 of them. Tracing every wallet the notes advertised gives five actors, eleven payments and $5,553 in total revenue, and shows the promise to return deleted data is unsupported by the evidence. elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin
Exposed Elasticsearch: Inside the Ransom-Wipe Economy
Kinryū Labs censused 17,043 internet-facing Elasticsearch hosts and found that a wiped husk with a ransom note in it is the single most common state of an exposed cluster: 5,073 of them. Tracing every wallet the notes advertised gives five actors, eleven payments and $5,553 in total revenue, and shows the promise to return deleted data is unsupported by the evidence.
elasticsearch · ransomware · extortion · data-exposure · on-chain-analysis · bitcoin
July 25, 2026 / Threat teardown godhive: A Novel Rust Crypto-Stealer and Miner Framework Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection. malware · cryptojacking · crypto-stealer · rust · docker · worm
July 25, 2026 / Threat teardown
godhive: A Novel Rust Crypto-Stealer and Miner Framework
Kinryū Labs analysed godhive, a novel and undocumented Rust offensive framework caught abusing an exposed Docker API on our honeypot network. It mines Monero, drains cryptocurrency wallets across major exchanges and more than eight blockchains, spreads as a worm, and hides behind a command channel built to survive takedown. We assess with high confidence that it is purpose-built crimeware, and that it was deployed by a single developer field-testing their own tool from a consumer mobile connection.
malware · cryptojacking · crypto-stealer · rust · docker · worm
July 7, 2026 / Threat teardown Inside a Gaming DDoS-for-Hire Operation Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel. malware · botnet · ddos · golang · iot · honeypot
July 7, 2026 / Threat teardown
Inside a Gaming DDoS-for-Hire Operation
Kinryū Labs assesses with high confidence that this is a commercial gaming DDoS-for-hire operation running on a shared botnet builder kit. The same Go codebase is compiled by different operators with their own C2 servers and attack loadouts; the fleet analysed here fronts a self-serve, account-gated for-hire API and a live bot inventory of roughly 28 to 32 devices, dispatching customer attack orders against gaming and voice infrastructure. Its raw-TCP command channel is unauthenticated while bot registration is gated behind a password-authenticated SSH channel.
malware · botnet · ddos · golang · iot · honeypot
July 2, 2026 / Threat teardown A Cross-Platform Go DDoS Botnet-for-Hire Kinryū Labs analysed bot.exe, the Windows build of a Go-compiled DDoS botnet distributed as an 11-binary, 13-architecture dropper suite and delivered through a multi-day Jenkins Script Console exploitation campaign. Reconnaissance of the staging host identified a live, authenticated DDoS-for-hire API, a Go SSH command channel, and a co-hosted Mirai-lineage family. We assess with high confidence that this is a commercial DDoS-for-hire operation. malware · botnet · ddos · golang · iot · jenkins
July 2, 2026 / Threat teardown
A Cross-Platform Go DDoS Botnet-for-Hire
Kinryū Labs analysed bot.exe, the Windows build of a Go-compiled DDoS botnet distributed as an 11-binary, 13-architecture dropper suite and delivered through a multi-day Jenkins Script Console exploitation campaign. Reconnaissance of the staging host identified a live, authenticated DDoS-for-hire API, a Go SSH command channel, and a co-hosted Mirai-lineage family. We assess with high confidence that this is a commercial DDoS-for-hire operation.
malware · botnet · ddos · golang · iot · jenkins
June 23, 2026 / Threat teardown Kworker: The Cryptominer That Brings Its Own Uninstaller Kinryū Labs caught an 8220-lineage cryptojacker turn an open, password-less Redis port into a root shell in five seconds. The dropper, a 636-line shell script called kworker, uninstalls Alibaba and Tencent cloud security agents with the vendors' own tools, spends 200 lines killing rival miners, backdoors SSH, hides an XMRig Monero miner behind fake ps, top and pstree, and tries to worm onward. malware · cryptomining · redis · linux · honeypot · monero
June 23, 2026 / Threat teardown
Kworker: The Cryptominer That Brings Its Own Uninstaller
Kinryū Labs caught an 8220-lineage cryptojacker turn an open, password-less Redis port into a root shell in five seconds. The dropper, a 636-line shell script called kworker, uninstalls Alibaba and Tencent cloud security agents with the vendors' own tools, spends 200 lines killing rival miners, backdoors SSH, hides an XMRig Monero miner behind fake ps, top and pstree, and tries to worm onward.
malware · cryptomining · redis · linux · honeypot · monero
June 19, 2026 / Coordinated disclosure / native.org An Open Kibana Exposed native.org's Trading Stack During threat intelligence research, Kinryū Labs found an unauthenticated Kibana belonging to native.org that exposed its full trading-stack architecture and logged live API keys in plaintext. native.org has restricted access and rotated the keys. coordinated-disclosure · kibana · elasticsearch · data-exposure · defi · cloud-misconfiguration
June 19, 2026 / Coordinated disclosure / native.org
An Open Kibana Exposed native.org's Trading Stack
During threat intelligence research, Kinryū Labs found an unauthenticated Kibana belonging to native.org that exposed its full trading-stack architecture and logged live API keys in plaintext. native.org has restricted access and rotated the keys.
coordinated-disclosure · kibana · elasticsearch · data-exposure · defi · cloud-misconfiguration
June 16, 2026 / Threat teardown / CVE-2026-31431 Rootpacket: A Linux Cryptojacking Toolkit That Hides in the Kernel Kinryū Labs analysed Rootpacket, a Linux cryptojacking toolkit that ships a kernel rootkit to fake CPU and memory usage, escalates to root through CVE-2026-31431 (an AF_ALG page-cache flaw that also escapes containers to the host), masquerades as an Intel driver, and disables the same exposed services rival miners use to get in. malware · cryptomining · rootkit · linux · kernel · monero
June 16, 2026 / Threat teardown / CVE-2026-31431
Rootpacket: A Linux Cryptojacking Toolkit That Hides in the Kernel
Kinryū Labs analysed Rootpacket, a Linux cryptojacking toolkit that ships a kernel rootkit to fake CPU and memory usage, escalates to root through CVE-2026-31431 (an AF_ALG page-cache flaw that also escapes containers to the host), masquerades as an Intel driver, and disables the same exposed services rival miners use to get in.
malware · cryptomining · rootkit · linux · kernel · monero
June 12, 2026 / Threat teardown Inside a RedTail Campaign: Self-Propagation Through Exposed Docker APIs Kinryū Labs honeypots caught the RedTail cryptominer spreading through unauthenticated Docker Engine APIs and dropped SSH keys. This writeup documents a current, fully captured instance, with the loader, the competitor-removal script, the miner, and live indicators. malware · cryptomining · redtail · docker · linux · honeypot
June 12, 2026 / Threat teardown
Inside a RedTail Campaign: Self-Propagation Through Exposed Docker APIs
Kinryū Labs honeypots caught the RedTail cryptominer spreading through unauthenticated Docker Engine APIs and dropped SSH keys. This writeup documents a current, fully captured instance, with the loader, the competitor-removal script, the miner, and live indicators.
malware · cryptomining · redtail · docker · linux · honeypot
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
