logo

P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances

ID: d6af2e66-4ac3-59f0-8688-ff538e0ccf74

STIX ID: report--d6af2e66-4ac3-59f0-8688-ff538e0ccf74

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Tushar Subhra Dutta

...
...

P2PInfect, a Rust-written P2P botnet active since mid-2023, has been observed compromising Kubernetes clusters (notably GKE) by abusing internet-exposed Redis instances and leveraging CVE-2022-0543 to execute code and enroll hosts into a decentralized mesh; infected nodes remain largely dormant but persistent, increasing the risk of future damaging payloads. FortiGuard Labs recommends not exposing Redis, patching, restricting replication, enforcing strict Kubernetes network policies, auditing outbound connections, and using runtime security tools to detect abnormal container behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.