The new Redigo malware targets Redis servers vulnerable to CVE-2022-0543, in order to install a backdoor and allow command execution.
See also: Cuba ransomware: How much money has the group made?

CVE-2022-0543 is a critical vulnerability in the Redis (Remote Dictionary Server) software. It has a maximum severity rating and was discovered and patched in February 2022.
Even after the fix was released, attackers continued to exploit the flaw on unpatched machines, since the proof-of-concept is publicly available.
The name “Redigo” was created from the engine it targets and the programming language required for its development – Go.
See also: Accuro: 30,000 customer data compromised due to hack
AquaSec today reports that Redis honeypots vulnerable to CVE-2022-0543 have detected a new piece of malware that is not detected as a threat by antivirus engines at Virus Total.

Redigo attacks
AquaSec reports that Redigo attacks begin with port 6379 scans to detect any exposed Redis servers on the open internet. After finding a target endpoint, the attacker connects and executes the following commands:
- INFO – Checks the Redis version to see if the server is vulnerable to CVE-2022-0543.
- SLAVEOF – Creating a copy of the server being attacked.
- REPLCONF – Configuration of the connection from the attacking server to the new replica.
- PSYNC – Start the playback stream and download the shared library 'exp_lin.so' to the server.
- MODULE LOAD – Loading module from the downloaded dynamic library, which is capable of executing arbitrary commands and exploiting CVE-2022-0543.
- SLAVEOF NO ONE – Make the vulnerable server the master.

Using the command execution capabilities of the implanted backdoor, attackers collect hardware information about the host and then download Redigo (redis-1.2-SNAPSHOT). The malware is executed after privilege.
Attackers use Redis communication over port 6379 to evade detection and hide traffic from the Redigo command and control server.
Due to limitations in the duration of the attack on AquaSec's honeypots, its analysts were unable to determine exactly what Redigo was doing after it established its foothold in the environment.

AquaSec believes that Redigo's end game is to either deploy the vulnerable server as a bot on a network for distributed denial-of-service (DDoS) attacks or use it for cryptocurrency mining.
See also: Bugs in Hyundai and other brands' mobile apps allowed vehicle hacking
Furthermore, since Redis is a database, it is also possible for someone to access the data and steal through Redigo attacks.
If you want to mitigate the impact of the Redis flaw, read the Debian security advisory or Ubuntu security bulletin regarding CVE-2022-0543.
Information source: bleepingcomputer.com
