Rust-Based P2PInfect Botnet Evolves with Miner and Ransomware Payloads
ID: ca609a7d-891b-553b-a335-0c99b8b6d23f
STIX ID: report--ca609a7d-891b-553b-a335-0c99b8b6d23f
Feed Name: The Hacker News
Threat Score
P2PInfect is an active Rust-based peer-to-peer botnet that targets misconfigured Redis servers to recruit victims into a mesh network and push updated payloads via a gossip mechanism. Recent updates add cryptocurrency miners, a ransomware component that encrypts files for 1 XMR, an LD_PRELOAD usermode rootkit to hide artifacts, SSH password-spraying, and scanning capabilities, indicating a financially motivated, opportunistic campaign likely operated as a botnet-for-hire.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
