Redis Instances Abuse

    Date: 09/21/2026

    Severity: High

    Summary 

    P2PInfect activity targeting internet-exposed and exploiting misconfigured Redis instances, with attackers abusing Redis replication and module-loading capabilities to achieve remote code execution. The campaign exploits CVE-2022-0543 and deploys ELF-based malware, establishes reverse shells, and uses mechanisms such as cron jobs and SSH authorized keys for persistence. The Rust-based P2PInfect worm further supports network scanning, SSH brute force, P2P propagation, anti-forensics, C2 communication, and cryptocurrency mining. 

    Indicators of Compromise (IOC) List 

    IP Address

    120.79.247.255

    101.133.145.177

    36.139.41.116

    124.236.108.172

    103.247.11.94

    106.75.16.140

    39.108.85.106

    124.236.108.141

    120.79.155.19

    106.12.152.213

    47.76.183.131

    47.242.16.134

    121.225.97.102

    47.86.176.78

    47.83.180.158

    47.238.150.36

    47.243.189.23

    8.210.80.120

    47.239.0.254

    43.99.83.70

    114.67.87.14

    Hash

    cf4c6ac09be225112faaef95316a137eff30e91c0f5f8e7aaf0a4bcc6c76f477

    07933668fe89067cf62fe8dc8d96018320577b8e5cedb2ee6fe09a6b53717cb5

    f12feb8785adcc2413a38e270a6867093d0fb62e08f5538f8a66d22ce60b2bd5

    976e3772ffea7499f7c119e956a5a71806f8f054caf174978fa888b254dd22a0

    a0082c4cbf2802f65ef7da85ebd8df314c184675180948808bb2aa9f5d873d6f

    b302e87dbb7fadfe38fae7515386a3a00be8030da17589a9e794c88d654e7081

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("103.247.11.94","47.86.176.78","120.79.247.255","124.236.108.172","124.236.108.141","47.243.189.23","120.79.155.19","47.83.180.158","121.225.97.102","43.99.83.70","47.242.16.134","47.239.0.254","8.210.80.120","114.67.87.14","101.133.145.177","106.12.152.213","106.75.16.140","36.139.41.116","39.108.85.106","47.238.150.36","47.76.183.131") or srcipaddress IN ("103.247.11.94","47.86.176.78","120.79.247.255","124.236.108.172","124.236.108.141","47.243.189.23","120.79.155.19","47.83.180.158","121.225.97.102","43.99.83.70","47.242.16.134","47.239.0.254","8.210.80.120","114.67.87.14","101.133.145.177","106.12.152.213","106.75.16.140","36.139.41.116","39.108.85.106","47.238.150.36","47.76.183.131")

    Detection Query 2 :

    sha256hash IN ("f12feb8785adcc2413a38e270a6867093d0fb62e08f5538f8a66d22ce60b2bd5","a0082c4cbf2802f65ef7da85ebd8df314c184675180948808bb2aa9f5d873d6f","07933668fe89067cf62fe8dc8d96018320577b8e5cedb2ee6fe09a6b53717cb5","b302e87dbb7fadfe38fae7515386a3a00be8030da17589a9e794c88d654e7081","cf4c6ac09be225112faaef95316a137eff30e91c0f5f8e7aaf0a4bcc6c76f477","976e3772ffea7499f7c119e956a5a71806f8f054caf174978fa888b254dd22a0")

    Reference: 

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-18-Redis-Instances-Abuse.txt     


    Tags

    MalwareExploitWormRust MalwarecryptocurrencyRCEELF Malwarereverse shellCVE-2022

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags