logo

HeadCrab 2.0 Goes Fileless, Targeting Redis Servers for Crypto Mining

ID: 4087c751-3caa-5aeb-84d1-b1412951f768

STIX ID: report--4087c751-3caa-5aeb-84d1-b1412951f768

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed HeadCrab 2.0, an evolved Redis-targeting malware that increasingly compromises internet-exposed Redis servers to form a crypto-mining botnet and enable remote command execution, fileless kernel module loading, and data exfiltration. The new variant abandons disk-based artifacts in favor of a fileless loader and leverages the Redis MGET command for stealthy C2, with Aqua reporting roughly 1,100 additional infected servers—evidence of active, financially motivated adaptation by the operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.