logo

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining

ID: 67f7d5c0-7b63-5219-9c48-fc20749463b4

STIX ID: report--67f7d5c0-7b63-5219-9c48-fc20749463b4

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A novel cryptojacking campaign involving a Golang ELF malware named Migo is actively targeting exposed Redis servers to gain access to Linux hosts, disable security controls (including SELinux), install persistence, hide artifacts using a modified libprocesshider, and deploy XMRig miners retrieved via Transfer.sh and Pastebin; the report details novel system‑weakening techniques, persistence steps, and overlap with tactics used by known cryptojacking groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.