HomeSecurityP2PInfect malware: Attacks on SSH and Redis to create botnets

P2PInfect malware: Attacks SSH and Redis to create botnets

P2PInfect malware: Attacks SSH and Redis to create botnets

Hackers are actively targeting exposed instances of SSH and the Redis open-source data store with a peer-to-peer self-replicating worm with versions for both Windows and Linux that malware authors have dubbed P2Pinfect.

See also: New P2PInfect worm-type malware targets Linux and Windows Redis servers

Written in Rust, the malware relies on at least two methods to establish itself: a critical vulnerability that was disclosed and patched last year, and a feature that allows for replication of the main database for high availability and to handle failure scenarios.

Exploiting Redis' replication capability

P2PInfect was initially recorded by researchers at Palo Alto Networks Unit 42, who found that it exploited the vulnerability identified as CVE-2022-0543.

The security issue is a vulnerability specific to Debian that allows remote code execution. After compromising a vulnerable Redis server, P2PInfect downloads new scripts and malicious binaries and adds the server to its network of infected systems.

P2PInfect
P2PInfect takes control via Redis replication function

Researchers found a sample of P2PInfect with cross-platform compatibility between Windows and Linux. The sample exploited the Redis replication feature, which is a common attack pattern against Redis in cloud environments. An attacker can connect to an exposed Redis instance and issue a specific command to trigger replication.

Preparing for botnet assimilation

The P2PInfect malware is able to compromise a vulnerable Redis server and add it to its network of infected systems.

Once infected, the malware updates the server's SSH settings and adds an SSH key to allow the attacker to log in. It then runs a script that checks for specific utilities and installs them if they are not present.

The script also renames the wget and curl binaries, adds iptables rules to control traffic to the Redis server, and installs persistence on the infected computer. The network of infected servers operates as a peer-to-peer botnet, allowing it to receive instructions without the need for a central command and control server.

Suggestion: Decoy Dog malware toolkit gains new features

Finding vulnerable servers

P2PInfect malware: Attacks SSH and Redis to create botnets

P2PInfect infects more computers by checking bash history for available IPs, users, and SSH keys. It scans for exposed SSH and Redis servers and gains access to weakly protected hosts using a list of passwords for brute-force attempts. With Redis servers, it will try to exploit vulnerabilities or the copy function to load malicious functions. There are over 307,000 Redis instances accessible over the internet, and P2PInfect is likely to scan them for weaknesses or vulnerabilities.

The purpose of P2PInfect remains unclear, but one possible clue is the presence of a binary file called “miner,” which could point to cryptocurrency mining activity.

However, Cado Security observed that the file was executed and then deleted, but there was no evidence of cryptomining. Instead, it continued to make the sleep syscall, which does nothing.

This may only be the initial stage of the campaign, and additional features, possibly cryptomining, will be added after a sufficient number of Redis instances are compromised.

Read also: Android malware CherryBlos steals passwords using OCR

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS