logo

P2PInfect Botnet Targets Kubernetes Clusters Through Misconfigured Redis Servers

ID: e87934be-4b1e-5883-91c8-014c359adc50

STIX ID: report--e87934be-4b1e-5883-91c8-014c359adc50

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Varshini

...
...

P2PInfect is a resilient peer-to-peer botnet actively exploiting exposed Redis instances and multiple recently disclosed RCE vulnerabilities (Metro4Shell, RediShell, React2Shell) to recruit nodes within GKE and enterprise environments; the report outlines the deployer.sh infection flow, weak ChaCha20 obfuscation, bootstrap peer lists, observed indicators (deployer.sh and two MD5 hashes), and highlights the botnet’s use as a botnet-for-hire for potential second-stage payloads like cryptominers or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.