logo

P2PInfect campaign (Campaign)

ID: 26b32533-e725-52be-9c2b-bb031cc457b5

STIX ID: report--26b32533-e725-52be-9c2b-bb031cc457b5

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2023-07-31

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A campaign is actively targeting misconfigured Redis servers using a peer-to-peer self-replicating worm called P2Pinfect; the malware (written in Rust) abuses Redis' SLAVEOF replication and exploits CVE-2022-0543 (a Debian-specific LUA sandbox escape, CVSS 10) to achieve remote code execution, download OS-specific payloads, and add infected servers to a botnet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.