Netskope Threat Labs

Kinsing

ATP Sandbox Adv. HeuristicsAV

Kinsing is a Golang based malware that runs cryptocurrency miners on compromised hosts and attempts to spread to other machines in the victim environment.

First seen
May 2022
Last seen
October 2026

17 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

  • T1133External Remote Services

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1018Remote System Discovery
  • T1057Process Discovery
  • T1083File and Directory Discovery

TA0008 Lateral Movement

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

  • T1222File and Directory Permissions Modification
Alert Name
Linux.Trojan.Kinsing
Trojan.Linux.Kinsing.C