P2PInfect botnet targets REdis servers with new ransomware module
ID: 79b9abf5-2850-591e-9f45-06e5863aac89
STIX ID: report--79b9abf5-2850-591e-9f45-06e5863aac89
Feed Name: Bleeping Computer
Threat Score
P2PInfect, a previously dormant peer-to-peer botnet targeting Redis servers, has begun actively deploying an rsagen ransomware module and a Monero cryptominer; it spreads using Redis replication and other persistence mechanisms, employs a user-mode rootkit to hide activity, and has generated measurable mining revenue while its ransomware is limited by the typical in-memory deployment of Redis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
