logo

Cloud Under Siege: Persistent P2Pinfect Botnet Activity Discovered in Kubernetes Environments

ID: 16a8e001-0844-5369-a19b-401b468b84af

STIX ID: report--16a8e001-0844-5369-a19b-401b468b84af

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-24

Date Updated: 2026-05-24

Author: Ddos

...
...

FortiGuard Labs identified a persistent, decentralized P2Pinfect botnet infecting Google Kubernetes Engine clusters by abusing exposed Redis instances and other misconfigurations. The Rust-based, peer-to-peer malware evades sinkholing, supports multiple OSes, uses non-standard ports, and is operated as a botnet-for-hire—enabling third parties to deploy ransomware or crypto-miners. The campaign persisted for months, has broadened initial access vectors (including Metro4Shell and a suspected sandbox escape dubbed RediShell), and the report urges immediate network hardening, patching, traffic monitoring, and deployment audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.