Your Redis Server Looks Fine. That’s the Problem.
ID: d8e042a4-11e1-51cd-8a7a-308016bf4f0e
STIX ID: report--d8e042a4-11e1-51cd-8a7a-308016bf4f0e
Feed Name: Security Boulevard
An automated operation is actively scanning and exploiting unsecured Redis instances to gain persistent root access by planting SSH keys and using multiple RCE techniques (cron file writes, Lua sandbox escape via CVE-2022-0543, replication hijacking and MODULE LOAD). Observed from a honeypot with over 1,200 attempts across multiple IPs and two distinct operator groups (a sophisticated SSH key operator and the MGLNDD botnet), the attack is optimized to clean up forensic traces and leave a single SSH public key for persistent access; recommended mitigations include not exposing Redis, setting strong passwords, patching, auditing authorized_keys, and monitoring for suspicious Redis commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
