logo

Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise

ID: f1cef024-037f-5f98-b3a1-a302365ce50a

STIX ID: report--f1cef024-037f-5f98-b3a1-a302365ce50a

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

...
...

FortiGuard Labs observed persistent P2Pinfect P2P botnet infections in multiple Google Kubernetes Engine clusters and exposed Redis hosts, using UPX-packed Rust binaries and a shell deployer to bootstrap nodes from an IP-hosted payload; telemetry links peer nodes and Metro4Shell exploitation beginning November 2025 and notes possible RediShell involvement. The botnet shows long dormancy with potential to deliver crypto-miners and ransomware, leverages non-standard ports and encoded nodelists for resilience, and includes detailed IOCs and Fortinet detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.