HomeSecurityRedigo malware: Installs backdoor on Redis servers

Redigo malware: Installs backdoor on Redis servers

The new Redigo malware targets Redis servers vulnerable to CVE-2022-0543, in order to install a backdoor and allow command execution.

See also: Cuba ransomware: How much money has the group made?

Redigo

CVE-2022-0543 is a critical vulnerability in the Redis (Remote Dictionary Server) software. It has a maximum severity rating and was discovered and patched in February 2022.

Even after the fix was released, attackers continued to exploit the flaw on unpatched machines, since the proof-of-concept is publicly available.

The name “Redigo” was created from the engine it targets and the programming language required for its development – ​​Go.

See also: Accuro: 30,000 customer data compromised due to hack

AquaSec today reports that Redis honeypots vulnerable to CVE-2022-0543 have detected a new piece of malware that is not detected as a threat by antivirus engines at Virus Total.

Redigo malware: Installs backdoor on Redis servers
Redigo payload comes out clean during Virus Total (AquaSec) scan

Redigo attacks

AquaSec reports that Redigo attacks begin with port 6379 scans to detect any exposed Redis servers on the open internet. After finding a target endpoint, the attacker connects and executes the following commands:

  • INFO – Checks the Redis version to see if the server is vulnerable to CVE-2022-0543.
  • SLAVEOF – Creating a copy of the server being attacked.
  • REPLCONF – Configuration of the connection from the attacking server to the new replica.
  • PSYNC – Start the playback stream and download the shared library 'exp_lin.so' to the server.
  • MODULE LOAD – Loading module from the downloaded dynamic library, which is capable of executing arbitrary commands and exploiting CVE-2022-0543.
  • SLAVEOF NO ONE – Make the vulnerable server the master.
Redigo malware: Installs backdoor on Redis servers

Using the command execution capabilities of the implanted backdoor, attackers collect hardware information about the host and then download Redigo (redis-1.2-SNAPSHOT). The malware is executed after privilege.

Attackers use Redis communication over port 6379 to evade detection and hide traffic from the Redigo command and control server.

Due to limitations in the duration of the attack on AquaSec's honeypots, its analysts were unable to determine exactly what Redigo was doing after it established its foothold in the environment.

Redigo

AquaSec believes that Redigo's end game is to either deploy the vulnerable server as a bot on a network for distributed denial-of-service (DDoS) attacks or use it for cryptocurrency mining.

See also: Bugs in Hyundai and other brands' mobile apps allowed vehicle hacking

Furthermore, since Redis is a database, it is also possible for someone to access the data and steal through Redigo attacks.

If you want to mitigate the impact of the Redis flaw, read the Debian security advisory or Ubuntu security bulletin regarding CVE-2022-0543.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS