Temporary Advertisements:
Ad
Ad
Ad
P2P Self-Replicating Cloud Worm Targets Redis
by ZackfromFuture - Thursday July 20, 2023 at 12:35 AM
#1
P2P Self-Replicating Cloud Worm Targets Redis

Although not all Redis instances are vulnerable to the P2P worm variant, all of them can expect a compromise attempt, researchers warn.

Researchers have identified a cross-platform, Rust-based, peer-to-peer (P2) worm that's targeting the Redis open-source database application; specifically, containers in the cloud. 

A July 19 report from Palo Alto Network's Unit 42 named the cloud worm an appropriate moniker: "P2PInfect." The team suspects, due to its substantial command-and-control (C2) network, and mentions of the word "miner," that it could be the first stage of a wider cryptomining operation.

While the Unit 42 team found more than 300,000 Redis systems online, not all are vulnerable to the P2Pinfect worm — in fact they found just 934 of those. The team said vulnerable Redis systems are unpatched against the Lua sandbox escape vulnerability tracked under CVE-2022-0543, which scores 10 out of 10 on the CVSS vulnerability-severity scale.

"While the vulnerability was disclosed in 2022, its scope is not fully known at this point," the Unit 42 P2P cloud worm report explained. "Additionally, the fact that P2PInfect exploits Redis servers running on both Linux and Windows operating systems makes it more scalable and potent than other worms."

The problem for the rest of the Redis user base is that Unit 42 analysts predict that every Redis system can expect threat actors to attempt a breach. And, it can be modified with additional compromise tactics at any time, meaning that Redis instances that are not vulnerable now could become crackable in the future.

"The P2P network appears to possess multiple C2 features such as 'Auto-updating' that would allow the controllers of the P2P network to push new payloads into the network that could alter and enhance the performance of any of the malicious operations," according to the report.

The Unit 42 added it will continue to track P2PInfect.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | https://breachforums.cx/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#2
Written very professionally

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scraping | Contact us via http://breached4wtyw5fb45zj7sggnoazgv3aohme2zftkrndhvo76d5q5uad.onion/misc.php?action=help&hid=27 if you feel this is incorrect.
Reply
#3
Scam scam scam
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 35 5,570 32 minutes ago
Last Post: agus123
  Breached forums and clones? fda5b 8 3,181 5 hours ago
Last Post: binaryplay
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 24 4,500 Yesterday, 04:17 PM
Last Post: krassimiryo
  Claude Mythos biyukean 7 1,104 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 20,117 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz

Forum Jump:


 Users browsing this forum: 1 Guest(s)