'P2PInfect' Worm Grows Teeth With Miner, Ransomware & Rootkit
ID: c1cbd3a0-2288-514d-93ef-b2dfa851b420
STIX ID: report--c1cbd3a0-2288-514d-93ef-b2dfa851b420
Feed Name: Dark Reading
P2PInfect is a Linux worm that leverages misconfigured Redis replication to propagate and form a P2P botnet; recent updates added a usermode rootkit, an active Monero miner (approximately 71 XMR mined), and a rudimentary ransomware module. While the ransomware appears poorly targeted for typical Redis deployments, the rootkit and cryptomining increase persistence and detection risk; infections are concentrated in East Asia and organizations should secure exposed Redis instances, restrict access, and monitor for CPU/disk spikes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
