Earlier this month, security researchers discovered new peer-to-peer (P2P) malware P2PInfect with self-propagating capabilities that targets Redis instances running on Windows and Linux systems exposed to the internet.

On July 11, researchers at Unit 42 discovered a Rust-based worm (named P2PInfect) that attacks Redis servers that have remained vulnerable to the high-severity CVE-2022-0543 Lua sandbox escape vulnerability.
In the last two weeks, 307,000 exposed Redis servers have been discovered online, however, according to researchers, only 934 of these instances are potentially vulnerable to attacks by this malware.
However, even if not all of them are vulnerable to infection, the worm still targets and tries to put them at risk.
Goals have been set for cloud container environments
Successful exploitation of the CVE-2022-0543 flaw allows malware to gain remote code execution on compromised devices.
After its deployment, the P2PInfect worm installs an initial malicious payload, creating a peer-to-peer (P2P) communication channel in a wider interconnected system.
After connecting to the P2P network of other infected devices used for automatic propagation, the worm downloads additional malicious binaries, including scanning tools to find other exposed Redis servers.
Over the years, many threat actors have targeted Redis servers, adding them to DDoS botnets and cryptojacking.
For example, CVE-2022-0543 exploits have been used for initial access by other botnets targeting Redis instances, such as Muhstik and Redigo, for various malicious purposes, including DDoS and brute-forcing.
In March 2022, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal civil agencies to patch a critical vulnerability in Redis, which had been added to the propagation exploit used by the Muhstik malware gang.
Unfortunately, based on the large number of cases exposed online, many Redis server administrators may not be aware that Redis does not have a secure by default configuration.
According to the official documentation, Redis servers are designed for closed IT networks and, therefore, do not have an access control mechanism enabled by default.
Information source: bleepingcomputer.com
