New P2PInfect Worm Targets Redis Servers with Undocumented Breach Methods

Teilen:

The P2PInfect peer-to-peer (P2) worm has been observed employing previously undocumented initial access methods to breach susceptible Redis servers and rope them into a botnet.

The malware compromises exposed instances of the Redis data store by exploiting the replication feature, Cado Security researchers Nate Bill and Matt Muir said in a report shared with The Hacker News.

A common attack pattern against Redis in cloud environments is to exploit this feature using a malicious instance to enable replication. This is achieved via connecting to an exposed Redis instance and issuing the SLAVEOF command.

The Rust-based malware was first documented by Palo Alto Networks Unit 42, calling out the malware’s ability to exploit a critical Lua sandbox escape vulnerability (CVE-2022-0543, CVSS score: 10.0) to obtain a foothold into Redis instances. The campaign is believed to have commenced on or after June 29, 2023.

However, the latest discovery suggests that the threat actors behind the campaign are leveraging multiple exploits for initial access.

This is not the first time the SLAVEOF command has been abused in the wild. Previously, threat actors associated with malware families such as H2Miner and HeadCrab have abused the attack technique to illicitly mine cryptocurrency on compromised hosts.

In doing so, the goal is to replicate a malicious instance and load a malicious module to activate the infection.

Another initial access vector entails the registration of a malicious cron job on the Redis host to download the malware from a remote server upon execution, a method previously observed in attacks mounted by the WatchDog cryptojacking group.

A successful breach is followed by the distribution of next-stage payloads that allow the malware to alter iptables firewall rules at will, upgrade itself, and potentially deploy cryptocurrency miners at a later date once the botnet has grown to a specific size.

The P2Pinfect malware makes use of a peer-to-peer botnet, the researchers said. Each infected server is treated as a node, which then connects to other infected servers. This allows the entire botnet to gossip with each other without using a centralized C2 server.

A notable trait of the botnet is its worming behavior, enabling it to expand its reach by using a list of passwords to brute-force SSH servers and attempting to exploit the Lua sandbox escape vulnerability or use the SLAVEOF command in the case of Redis servers.

The identity of the threat actors behind the campaign is currently unknown and the purpose of P2PInfect remains unclear, with Unit 42 previously noting that the indicators don’t overlap with any of the known cryptojacking groups.

P2Pinfect is well-designed and utilizes sophisticated techniques for replication and C2, the researchers concluded. The choice of using Rust also allows for easier portability of code across platforms (with the Windows and Linux binaries sharing a lot of the same code), while also making static analysis of the code significantly harder.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:53 pm, Juni 30, 2025
Wetter-Symbol 24°C
L: 23° | H: 25°
klarer Himmel
Luftfeuchtigkeit: 66 %
Druck: 1014 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
23° | 25°°C 0 mm 0% 11 mph 67 % 1015 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
19° | 26°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 7 mph 53 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 10 mph 47 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 12 mph 90 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 24°°C 0 mm 0% 3 mph 67 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
21° | 23°°C 0 mm 0% 3 mph 66 % 1015 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 5 mph 63 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
28° | 28°°C 0 mm 0% 3 mph 44 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
34° | 34°°C 0 mm 0% 8 mph 26 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 46 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,726.36
0.08%
Ethereum(ETH)
€2,141.69
2.99%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.95
4.59%
Solana(SOL)
€134.28
4.10%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142338
1.58%
Shiba Inu(SHIB)
€0.000010
0.00%
Pepe(PEPE)
€0.000009
2.69%
Nach oben scrollen