logo

RedisRaider: Weaponizing misconfigured Redis to mine cryptocurrency at scale

ID: c8ec2c26-b992-5271-9291-a0ae7eb5071d

STIX ID: report--c8ec2c26-b992-5271-9291-a0ae7eb5071d

Feed Name: Datadog Security Labs

Threat Score
72/100

Date Published: 2025-05-07

Date Updated: 2026-04-27

...
...

Datadog Security Research describes RedisRaider, a Go-based cryptojacking worm that aggressively scans the IPv4 space for exposed Redis instances, exploits misconfigured/unauthenticated servers by writing short‑TTL Redis keys and using CONFIG/BGSAVE to place cron jobs in /etc/cron.d, then downloads and unpacks a packed XMRig miner (and also hosts an in-browser Monero miner). The report includes technical analysis of the dropper and unpacking routines, obfuscation techniques (Garble and custom packing), runtime behaviors, example commands and logs, IOCs (domain, IP, payload URLs, and SHA-256 hashes), and mitigation recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.