logo

New Linux Malware “Migo” Exploits Redis for Cryptojacking, Disables Security

ID: 707effb7-0984-5457-a29c-991307bc3861

STIX ID: report--707effb7-0984-5457-a29c-991307bc3861

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Migo is a Golang-based Linux cryptominer that compromises exposed Redis servers by issuing "system weakening" Redis commands to disable protections, fetch and run an XMRig miner, and persist via systemd while using compile-time obfuscation and a user-mode rootkit (libprocesshider) to hide processes and artefacts, making detection and forensics difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.