New P2PInfect Worm Targets Redis Servers with Undocumented Breach Methods

Teilen:

The P2PInfect peer-to-peer (P2) worm has been observed employing previously undocumented initial access methods to breach susceptible Redis servers and rope them into a botnet.

The malware compromises exposed instances of the Redis data store by exploiting the replication feature, Cado Security researchers Nate Bill and Matt Muir said in a report shared with The Hacker News.

A common attack pattern against Redis in cloud environments is to exploit this feature using a malicious instance to enable replication. This is achieved via connecting to an exposed Redis instance and issuing the SLAVEOF command.

The Rust-based malware was first documented by Palo Alto Networks Unit 42, calling out the malware’s ability to exploit a critical Lua sandbox escape vulnerability (CVE-2022-0543, CVSS score: 10.0) to obtain a foothold into Redis instances. The campaign is believed to have commenced on or after June 29, 2023.

However, the latest discovery suggests that the threat actors behind the campaign are leveraging multiple exploits for initial access.

This is not the first time the SLAVEOF command has been abused in the wild. Previously, threat actors associated with malware families such as H2Miner and HeadCrab have abused the attack technique to illicitly mine cryptocurrency on compromised hosts.

In doing so, the goal is to replicate a malicious instance and load a malicious module to activate the infection.

Another initial access vector entails the registration of a malicious cron job on the Redis host to download the malware from a remote server upon execution, a method previously observed in attacks mounted by the WatchDog cryptojacking group.

A successful breach is followed by the distribution of next-stage payloads that allow the malware to alter iptables firewall rules at will, upgrade itself, and potentially deploy cryptocurrency miners at a later date once the botnet has grown to a specific size.

The P2Pinfect malware makes use of a peer-to-peer botnet, the researchers said. Each infected server is treated as a node, which then connects to other infected servers. This allows the entire botnet to gossip with each other without using a centralized C2 server.

A notable trait of the botnet is its worming behavior, enabling it to expand its reach by using a list of passwords to brute-force SSH servers and attempting to exploit the Lua sandbox escape vulnerability or use the SLAVEOF command in the case of Redis servers.

The identity of the threat actors behind the campaign is currently unknown and the purpose of P2PInfect remains unclear, with Unit 42 previously noting that the indicators don’t overlap with any of the known cryptojacking groups.

P2Pinfect is well-designed and utilizes sophisticated techniques for replication and C2, the researchers concluded. The choice of using Rust also allows for easier portability of code across platforms (with the Windows and Linux binaries sharing a lot of the same code), while also making static analysis of the code significantly harder.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:01 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
broken clouds
Luftfeuchtigkeit: 90 %
Druck: 1013 mb
Wind: 10 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 5 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0.43 mm 43% 13 mph 92 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.25 mm 25% 16 mph 75 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,182.86
-2.33%
Ethereum(ETH)
€2,242.26
-5.35%
Fesseln(USDT)
€0.88
0.03%
XRP(XRP)
€2.06
-4.69%
Solana(SOL)
€153.88
-3.86%
USDC(USDC)
€0.88
0.01%
Dogecoin(DOGE)
€0.200672
-7.80%
Shiba Inu(SHIB)
€0.000012
-7.28%
Pepe(PEPE)
€0.000012
-10.99%
Peanut das Eichhörnchen(PNUT)
€0.306727
-7.85%
Nach oben scrollen