Cloud Under Siege: Persistent P2Pinfect Botnet Activity Discovered in Kubernetes Environments
ID: 16a8e001-0844-5369-a19b-401b468b84af
STIX ID: report--16a8e001-0844-5369-a19b-401b468b84af
Feed Name: securityonline.info
FortiGuard Labs identified a persistent, decentralized P2Pinfect botnet infecting Google Kubernetes Engine clusters by abusing exposed Redis instances and other misconfigurations. The Rust-based, peer-to-peer malware evades sinkholing, supports multiple OSes, uses non-standard ports, and is operated as a botnet-for-hire—enabling third parties to deploy ransomware or crypto-miners. The campaign persisted for months, has broadened initial access vectors (including Metro4Shell and a suspected sandbox escape dubbed RediShell), and the report urges immediate network hardening, patching, traffic monitoring, and deployment audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
