logo

New Migo malware disables protection features on Redis servers

ID: 4b5174d8-0823-5581-b0ca-0693d648b931

STIX ID: report--4b5174d8-0823-5581-b0ca-0693d648b931

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-02-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Migo is a cryptomining malware campaign observed targeting exposed Redis servers on Linux; attackers use Redis CLI commands to disable security features, fetch a UPX-packed Go binary that installs a modified XMRig miner, and employ persistence and stealth (cron/systemd services, /etc/ld.so.preload user‑mode rootkit), while also disabling SELinux and cloud monitoring to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.