logo

'P2PInfect' Worm Grows Teeth With Miner, Ransomware & Rootkit

ID: c1cbd3a0-2288-514d-93ef-b2dfa851b420

STIX ID: report--c1cbd3a0-2288-514d-93ef-b2dfa851b420

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-25

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

P2PInfect is a Linux worm that leverages misconfigured Redis replication to propagate and form a P2P botnet; recent updates added a usermode rootkit, an active Monero miner (approximately 71 XMR mined), and a rudimentary ransomware module. While the ransomware appears poorly targeted for typical Redis deployments, the rootkit and cryptomining increase persistence and detection risk; infections are concentrated in East Asia and organizations should secure exposed Redis instances, restrict access, and monitor for CPU/disk spikes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.