HeadCrab: A Novel State-of-the-Art Redis Malware
ID: 554d117d-6a53-5fc3-a6e2-929b1960195c
STIX ID: report--554d117d-6a53-5fc3-a6e2-929b1960195c
Feed Name: Aqua Security Blog
Threat Score
Aqua Nautilus researchers uncovered "HeadCrab", an advanced Redis module malware and botnet that uses the SLAVEOF replication feature to load a memory-only malicious module (via memfd) into exposed Redis servers, enabling stealthy cryptomining (XMRig), encrypted C2, reverse shells, kernel-module loading, and persistence; the report includes a technical breakdown, IOCs (MD5, Monero wallet, IPs), detection methods, MITRE mappings, and remediation/hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
