logo

Redis honeypot: server with vulnerable Redis database reveals new SkidMap modification used to hide cryptocurrency mining process

ID: 9429554a-cce6-56ce-abdf-04cd97ff4c9f

STIX ID: report--9429554a-cce6-56ce-abdf-04cd97ff4c9f

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2024-10-03

Date Updated: 2026-04-27

...
...

**Doctor Web** reports a new Skidmap Linux rootkit delivered via a MulDrop dropper that installs a kernel-mode rootkit (Linux.Rootkit.400), the Linux.BtcMine.815/XMRig miner, multiple SSH/credential-theft backdoors (Linux.BackDoor.Pam.8, Linux.BackDoor.SSH.425) and a remote access trojan (Linux.BackDoor.RCTL.2); the rootkit spoofs CPU, network, and file listings to hide mining activity, attackers target exposed Redis/enterprise servers for large-scale cryptomining and persistence, and the report includes IOCs and observed campaign activity from a year-long honeypot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.