Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Kinsing is Linux malware whose central purpose is to run a cryptocurrency miner, while also attempting to spread to other hosts. It has reached container environments through more than one route: a documented 2020 campaign abused Docker Engine API ports exposed without adequate protection, while Microsoft’s 2023 reporting on Kubernetes described weak PostgreSQL container configurations and vulnerable images as initial access paths. Those are separate observed methods, not a universal infection sequence.

What is Kinsing malware?

MITRE ATT&CK describes Kinsing as Golang-based malware that runs a cryptocurrency miner and attempts to spread to other hosts. Its profile lists Linux and Containers as platforms and includes behaviors such as shell execution, SSH brute force, and HTTP command-and-control communications. These capabilities matter because a mining process may be only one visible part of a broader compromise.

Microsoft Defender for Cloud security researcher Sunders Bruskin wrote in a January 5, 2023 post: “Kinsing is a known malware that targets Linux environments for cryptocurrency purposes.” The mining objective is central, but the malware’s documented spread and credential-related activity mean defenders should not treat the incident as merely an unwanted process to kill.

How does Kinsing infect Docker containers?

A 2020 campaign report described attackers reaching Docker environments through Docker Engine API ports exposed without adequate protection. In the reported pattern, an attacker started a rogue Ubuntu container, fetched Kinsing and a miner, and then attempted to spread to other containers and hosts. CERT-In also reported that the campaign collected local SSH credentials and used scripts to remove competing malware. These details describe that campaign; they do not establish that every Kinsing infection follows the same steps.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Aqua Security attributed “thousands of attempts” nearly daily to the campaign it observed in its period-specific reporting. That historical figure is not a current infection count, does not measure all affected organizations, and should not be read as a present-day activity rate. The detailed Docker API campaign is historical, so its method is most useful as a warning about exposed management interfaces, not as a current prevalence measure.

Can Kinsing spread through Kubernetes?

Yes. Kinsing activity is not limited to exposed Docker APIs. In a January 2023 report on Kubernetes environments, Microsoft described weakly configured PostgreSQL containers and vulnerable images as common initial access methods. Its example showed a pattern in which a script is downloaded and executed inside a container.

This makes both configuration and image provenance relevant. An exposed or weakly configured database service can provide an entry point, while a vulnerable or untrusted image can introduce risk through the software deployed into the cluster. The Microsoft report documents observed paths, not a claim that every Kubernetes infection begins in PostgreSQL or an image.

How can I detect Kinsing in a Linux container?

Look for behavior as well as filenames or process names. Microsoft’s Kubernetes research identifies alerts that can detect suspicious activity, including a sequence in which files are downloaded and then executed. MITRE’s profile also records shell execution, SSH brute force, and HTTP command-and-control communications as Kinsing behaviors. These signals can help focus investigation, but no single alert or indicator proves that a system is infected.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review container and host telemetry for unexpected shell activity and suspicious download-then-execute sequences.
  • Investigate unusual outbound HTTP communications and unexpected SSH authentication attempts, particularly when they occur alongside unfamiliar processes or files.
  • Correlate activity across the affected container, its host, and other workloads to determine whether there are signs of spread.
  • Use current threat intelligence to validate indicators before blocking or searching on them. Historical addresses and campaign indicators can change and should not be treated as current without verification.

Microsoft’s April 2025 overview offers broader container-security context, but it is not a new Kinsing-specific campaign report. It should not be used to infer a current Kinsing rate or fresh indicators.

How do I reduce the risk of a crypto miner in Docker or Kubernetes?

Prevention reduces exposure to weak configurations and vulnerable software; detection helps identify suspicious behavior that gets through. Neither is sufficient alone. Prioritize controls that address the documented paths and the malware’s ability to spread.

Reduce exposure at management and service interfaces

  • Limit access to Docker management interfaces, and do not expose a Docker Engine API without suitable protection.
  • Review database and container configurations, including PostgreSQL services, for weak or unintended access paths.

Protect images and credentials

  • Check the provenance and contents of deployed images, and address vulnerable images before they enter workloads.
  • Protect SSH credentials and investigate possible credential exposure if a container or host is compromised.

Monitor execution and network behavior

  • Alert on suspicious downloads followed by execution, unexpected shell activity, and unusual outbound communications.
  • Use host and container monitoring together so an investigation can identify activity beyond the first visible workload.

These controls reduce risk; they cannot guarantee that Kinsing or other malware will be prevented.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I do if I suspect a Kinsing infection?

Follow your organization’s incident-response process and current platform or vendor guidance. Do not assume that deleting a visible miner process removes the compromise: persistence, credentials already collected, or other affected workloads may remain. Verify the environment and assess credential exposure as part of the response. The available reporting documents multiple behaviors and entry paths, but does not establish one universal cleanup procedure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not run old campaign scripts or treat historical command-and-control addresses as safe or current. If you use indicators from past reports, confirm them against current threat intelligence and preserve the source and observation date when using them for detection or blocking.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.