RedisRaider Linux Cryptojacking Campaign Targets Redis Servers (Campaign)
ID: 3554980c-ffde-5313-83e7-d9ae8b3e59be
STIX ID: report--3554980c-ffde-5313-83e7-d9ae8b3e59be
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-05-08
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
RedisRaider is an active cryptojacking campaign that indiscriminately scans for Redis servers exposed on port 6379, abuses misconfigured Redis to write a base64-encoded cron job to /etc/cron.d/apache, downloads a Go-based ELF payload (from a.hbweb.icu) which unpacks an XMRig miner at runtime, and uses obfuscation and log-cleaning to evade analysis; additional infrastructure hosts an in-browser Monero miner.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
