Also known as: Money Libra
This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear if they conducted the attacks themselves, or if they bought leaked databases from third parties.
Executive Summary
Kinsing, also known as Money Libra, is a criminal threat actor that emerged in the first quarter of 2022, publishing samples of alleged stolen data from companies on their Tor site. The group's primary motivation and sophistication level are unclear, but their actions suggest a focus on financial gain through data extortion. Kinsing's true capabilities and intentions remain uncertain, making them a volatile and potentially significant threat.
Goals & Targeting
Kinsing's strategic objectives appear to be financially motivated, with a focus on extorting money from companies by threatening to release sensitive data. Their targeting profile seems to be opportunistic, potentially targeting any sector or country where they can obtain valuable data. Typical victims of Kinsing may include companies with valuable intellectual property, customer data, or other sensitive information that could be leveraged for extortion. The group's willingness to operate openly on the dark web suggests they are seeking to maximize their impact and leverage public fear to achieve their goals.
Enhanced Description
Further analysis of Kinsing's activities and the context in which they operate is necessary to fully comprehend their threat posture. This includes examining the types of data they target, the sectors and geographies they focus on, and any potential links to other cybercrime groups or state-sponsored actors. Given the fluid nature of the cyber threat landscape, continuous monitoring and intelligence gathering on Kinsing and similar actors are essential for staying ahead of emerging threats and mitigating potential risks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Kinsing's campaign patterns are characterized by the public release of stolen data on the Tor network, aiming to extort money from affected companies. The operational tempo and victim types suggest a focus on high-impact, low-frequency operations, where the group leverages the fear of data release to achieve financial gain. Notable past operations include the publication of alleged stolen data from various companies, though the extent of their involvement in these breaches remains unclear. Continuous monitoring is required to understand their evolving tactics and targeting preferences.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Kinsing is moderate, with significant information gaps regarding their operational capabilities, true motivations, and the extent of their involvement in data breaches. Further intelligence gathering and analysis are necessary to fully understand the threat posed by this actor and to develop effective countermeasures.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
20
IOCs
0
Observed Data
0
Tactics