P2PInfect Strikes Redis Servers: How Botnet Chaos Unleashes Ransomware and Cryptominers

P2PInfect, once a sleepy botnet, has awakened with a vengeance! Now deploying ransomware and a cryptominer, this malware is wreaking havoc on Redis servers. Redis users, brace yourselves—your data might be locked, and your CPU cycles hijacked by this “botnet for hire.”

Hot Take:

So P2PInfect finally woke up from its long nap and decided to throw a ransomware party with a side of crypto mining. Redis servers, brace yourselves; this botnet is no longer just lurking in the shadows!

Key Points:

  • P2PInfect has transitioned from dormancy to active deployment of ransomware and cryptominer on Redis servers.
  • First documented in July 2023, the botnet utilizes Redis replication features for propagation.
  • New features include cron-based persistence, fallback communication, and SSH lockout.
  • Recent updates target 32-bit MIPS processors in routers and IoT devices.
  • Ransomware and cryptominer modules are now operational, causing significant disruptions and financial gains for the attackers.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here