logo

P2PInfect botnet targets REdis servers with new ransomware module

ID: 79b9abf5-2850-591e-9f45-06e5863aac89

STIX ID: report--79b9abf5-2850-591e-9f45-06e5863aac89

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

P2PInfect, a previously dormant peer-to-peer botnet targeting Redis servers, has begun actively deploying an rsagen ransomware module and a Monero cryptominer; it spreads using Redis replication and other persistence mechanisms, employs a user-mode rootkit to hide activity, and has generated measurable mining revenue while its ransomware is limited by the typical in-memory deployment of Redis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.