logo

Aqua Nautilus Discovers Redigo — New Redis Backdoor Malware

ID: c04de623-913d-5912-a3e4-9db04edfb217

STIX ID: report--c04de623-913d-5912-a3e4-9db04edfb217

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-12-01

Date Updated: 2026-04-26

...
...

Aqua Nautilus documented a novel Go-based backdoor called Redigo that exploits CVE-2022-0543 in Redis' Lua sandbox to load a malicious shared object and deploy a stealthy binary (redis-1.2-SNAPSHOT). The malware disguises command-and-control as normal Redis replication/cluster traffic over port 6379, was undetected by VirusTotal vendors, and was observed communicating with an attacker-controlled IP (45.41.240.51); the report provides the attack flow, network/process detections (eBPF/Tracee), IOCs (IP and MD5s), and hardening and runtime-monitoring recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.