P2PInfect Botnet Targets Kubernetes Clusters Through Misconfigured Redis Servers
ID: e87934be-4b1e-5883-91c8-014c359adc50
STIX ID: report--e87934be-4b1e-5883-91c8-014c359adc50
Feed Name: Cyber Press
P2PInfect is a resilient peer-to-peer botnet actively exploiting exposed Redis instances and multiple recently disclosed RCE vulnerabilities (Metro4Shell, RediShell, React2Shell) to recruit nodes within GKE and enterprise environments; the report outlines the deployer.sh infection flow, weak ChaCha20 obfuscation, bootstrap peer lists, observed indicators (deployer.sh and two MD5 hashes), and highlights the botnet’s use as a botnet-for-hire for potential second-stage payloads like cryptominers or ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
