Aqua Nautilus Discovers Redigo — New Redis Backdoor Malware
ID: c04de623-913d-5912-a3e4-9db04edfb217
STIX ID: report--c04de623-913d-5912-a3e4-9db04edfb217
Feed Name: Aqua Security Blog
Aqua Nautilus documented a novel Go-based backdoor called Redigo that exploits CVE-2022-0543 in Redis' Lua sandbox to load a malicious shared object and deploy a stealthy binary (redis-1.2-SNAPSHOT). The malware disguises command-and-control as normal Redis replication/cluster traffic over port 6379, was undetected by VirusTotal vendors, and was observed communicating with an attacker-controlled IP (45.41.240.51); the report provides the attack flow, network/process detections (eBPF/Tracee), IOCs (IP and MD5s), and hardening and runtime-monitoring recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
