• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

‘Worm-like’ botnet malware targeting popular Redis storage tool

31 July 2023
in Mining
Reading Time: 4 mins read
A A
0
‘Worm-like’ botnet malware targeting popular Redis storage tool
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

An unknown group of hackers is using a novel strain of malware to attack publicly accessible deployments of Redis — a popular data storage tool used by major companies like Amazon, Hulu and Tinder.

Researchers from Cado Security Labs explained that what stood out most was the fact that the malware appears to be a worm — a subset of malware that can propagate or self-replicate from one computer to another without human activation after breaching a system.

The researchers said they recently encountered the malware, which they labeled “P2Pinfect,” and were alarmed at its ability to self-propagate and spread itself to other vulnerable Redis deployments. The report does not name specific victims of the malware, and Cado Security said it is unclear what the botnet’s purpose is.

The hacking campaign was initially analyzed by Palo Alto’s Unit 42 in a report on July 19, which found the malware exploiting CVE-2022-0543 to take over Redis applications and add them to a botnet — a group of computers that have been infected in a way that allows a hacker to control them all.

That vulnerability was used to take over devices and add them to the Muhstik botnet in 2022, but it appears P2PInfect is part of a different malicious network and is not related to Muhstik, Unit 42 said.

The report from Cado Security mirrors much of what was found by Unit 42, including that the malware is written in the Rust programming language and tries to infect other hosts once it connects one to the botnet.

But Cado Security found two key differences. One was the method of entry: The malware sample found by the researchers did not use CVE-2022-0543 as the initial access vector. And another difference was that P2Pinfect targeted both Windows and Linux Redis instances.

Both security companies said the use of the Rust programming language made it easier for the malware to be used on both Windows and Linux platforms while also making it difficult for researchers to analyze the code.

“It’s not clear who is behind this or their ultimate goal. A file named ‘miner’ is being pulled by compromised systems however it doesn’t perform crypto mining tasks,” a Cado Security spokesperson told Recorded Future News. “This could be a placeholder for a crypto miner ready for when the threat actor wants to distribute it.”

Unit 42 similarly found the word “miner” throughout P2PInfect’s malicious toolkit but also did not see “any definitive evidence that cryptomining operations ever occurred.”

307,000 unique Redis systems

Cado Security researchers saw multiple Redis exploits used to gain initial access. The experts warned that the malware conducts internet scans for vulnerable Redis servers and self replicates in a “worm-like” manner.

“The malware compromises exposed instances of the Redis data store by exploiting the replication feature. Replication allows instances of Redis to be run in a distributed manner, in what’s referred to as a leader/follower topology,” the researchers said in a report.

“This allows follower nodes to act as exact replicas of the leader, providing high availability and failover for the data store. A common attack pattern against Redis in cloud environments is to exploit this feature using a malicious instance to enable replication.”

Cado has seen this initial access method used since 2018 in other attacks involving cloud malware campaigns — including H2miner and Headcrab.

Unit 42 said it identified more than 307,000 unique Redis systems communicating publicly over the last two weeks, “of which 934 may be vulnerable to this P2P worm variant.” Most are not vulnerable but Unit 42 said it was likely the worm would still attempt to compromise them.

Unit 42 said the malware was found in multiple geographic regions and the number of infected hosts is growing. The researchers said they did not have an estimate of how large the botnet had become.

The malware, according to Cado Security, allows the hackers to prevent other threat actors from compromising the Redis server while also allowing it to continue operating legitimately so the owners do not suspect something is wrong.

Once the malware is used, the infected server becomes a node in a peer-to-peer botnet.

“This allows the entire botnet to gossip with each other without using a centralised C2 server. It is assumed that commands are issued by propagating signed messages across the network,” the researchers said.

The malware will try to infect more hosts by gathering a list of users, IP addresses and access keys for the SSH network communication protocol.

“Once access is gained to a host, it infects it in the same way the initial compromised server was, by dropping a copy of itself (fetched from the built in HTTP server) and executing it with a nodelist as an argument,” they said.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Jonathan Greig

Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



Source link

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: BotnetMalwarePopularRedisStorageTargetingToolWormlike
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Congress wants answers over App Store NFT rules

Next Post

Bitcoin Power Players: Highlights From the Mining Disrupt Conference

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Bitcoin Power Players: Highlights From the Mining Disrupt Conference

Bitcoin Power Players: Highlights From the Mining Disrupt Conference

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana Surges as TVL Hits B and Market Cap Overtakes BNB – CoinCentral

Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral

12 September 2025
Solana (SOL) Price News: Galaxy Scoops Up Over 0M in SOL From Binance, Coinbase – CoinDesk

Solana (SOL) Price News: Galaxy Scoops Up Over $700M in SOL From Binance, Coinbase – CoinDesk

12 September 2025
Can It Reach 500% Gains in September?

Can It Reach 500% Gains in September?

12 September 2025
Retail Skips SHIB and DOGE for a Sub- DeFi Project Targeting 900% Before Year End

Retail Skips SHIB and DOGE for a Sub-$1 DeFi Project Targeting 900% Before Year End

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral
  • Solana (SOL) Price News: Galaxy Scoops Up Over $700M in SOL From Binance, Coinbase – CoinDesk
  • Can It Reach 500% Gains in September?
  • Retail Skips SHIB and DOGE for a Sub-$1 DeFi Project Targeting 900% Before Year End
  • SOL Breaks $230, Touches $240 for First Time Since January – Is Solana Season Finally Here? – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,089.00
  • ethereumEthereum (ETH) $ 4,523.95
  • xrpXRP (XRP) $ 3.04
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 239.78
  • bnbBNB (BNB) $ 908.48
  • usd-coinUSDC (USDC) $ 0.999761
  • dogecoinDogecoin (DOGE) $ 0.262540
  • staked-etherLido Staked Ether (STETH) $ 4,515.01
  • tronTRON (TRX) $ 0.348283
  • cardanoCardano (ADA) $ 0.889557
  • wrapped-stethWrapped stETH (WSTETH) $ 5,477.59
  • chainlinkChainlink (LINK) $ 24.39
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,877.16
  • hyperliquidHyperliquid (HYPE) $ 56.15
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,937.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.63
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.393100
  • wrapped-eethWrapped eETH (WEETH) $ 4,857.76
  • avalanche-2Avalanche (AVAX) $ 28.44
  • bitcoin-cashBitcoin Cash (BCH) $ 590.38
  • wethWETH (WETH) $ 4,520.52
  • hedera-hashgraphHedera (HBAR) $ 0.239745
  • litecoinLitecoin (LTC) $ 115.78
  • leo-tokenLEO Token (LEO) $ 9.55
  • crypto-com-chainCronos (CRO) $ 0.253870
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999457
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 114,954.00
  • polkadotPolkadot (DOT) $ 4.21
  • whitebitWhiteBIT Coin (WBT) $ 43.72
  • uniswapUniswap (UNI) $ 10.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199948
  • mantleMantle (MNT) $ 1.62
  • ethenaEthena (ENA) $ 0.751674
  • moneroMonero (XMR) $ 277.46
  • aaveAave (AAVE) $ 313.50
  • bitget-tokenBitget Token (BGB) $ 4.90
  • daiDai (DAI) $ 0.999968
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 195.65
  • memecoreMemeCore (M) $ 2.20
  • jito-staked-solJito Staked SOL (JITOSOL) $ 294.84
  • ondo-financeOndo (ONDO) $ 1.08
  • nearNEAR Protocol (NEAR) $ 2.72