The latest variants of the P2Pinfect botnet are now focused on infecting devices with 32-bit MIPS (Microprocessor without Interlocked Pipelined Stages) processors, such as routers and IoT.
See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

Due to their efficiency and compact design, MIPS processors are widespread in embedded systems such as routers, home gateways, and video game consoles.
P2Pinfect was discovered in July 2023 by analysts at Palo Alto Networks (Unit 42) as a new Rust-based worm that attacks vulnerable Redis affected by CVE-2022-0543. After its initial detection, security analysts at Cado reported that P2Pinfect exploits the Redis replication feature to propagate itself by creating copies.
Later, in September, Cado warned of increased activity by the P2Pinfect botnet targeting systems in the United States, Germany, the United Kingdom, Japan, Singapore, Hong Kong, and China.
Today, Cado reports a new development regarding the botnet, which marks a significant advancement in its targeting scope and its ability to evade detection. The most recent attacks observed in Cado honeypots look for SSH servers using weak credentials and attempt to upload the MIPS binary via SFTP and SCP.
The spread for the MIPS variant is not limited to SSH, as researchers have detected attempts to run the Redis server on MIPS devices via an OpenWRT named 'redis-server'. During static analysis, Cado researchers observed that the new P2Pinfect is a 32-bit ELF binary with no debugging information and includes a built-in 64-bit Windows, which acts as a loadable module for Redis, to allow shell commands to be executed on the host computer.
See also: Malware and ransomware still pose the biggest threats in cyberspace

The latest variant of P2Pinfect implements complex and multifaceted evasion mechanisms that make it significantly more difficult to detect and analyze. Cado has identified the following evasion mechanisms introduced in the latest version of P2Pinfect:
- Implement a check for the ' TracerPid ' value in the process state file to determine if analysis tools are tracking the malware process and terminate it if so.
- Use systematic calls to disable memory footprints that contain traces of its activity, thereby preventing the storage of memory content in the Linux kernel.
- The embedded DLL contains a function to avoid virtual machines (VM).
The continuous development of P2Pinfect and the expansion of its targeting of malicious software shows a high level of skill and determination by its creators. It is important to emphasize that despite extensive monitoring of the botnet through various campaigns over time, Cado Security remains uncertain about the exact objectives of the malicious software operators. These objectives can include cryptocurrency mining, executing DDoS attacks, facilitating traffic prefetching, and carrying out data theft.
See also: The possible existence of Chinese malware in US systems is a "ticking time bomb"
One of the most effective measures to protect against the P2PInfect botnet is to update and install the latest software updates. Software manufacturers often release updates that fix known security issues. By installing these updates, vulnerability to P2PInfect botnet attacks can be reduced.
Another effective protection measure is to use up-to-date antivirus software. These programs can detect and remove the malware used by the P2PInfect botnet. By choosing a reliable antivirus software and keeping it up-to-date, effective protection.
Furthermore, installing a personal firewall can be an effective protective measure. The personal firewall can monitor and filter incoming and outgoing data traffic, limiting the access of the P2PInfect botnet to the system.
Finally, user training is an important protective measure. Users must be informed about the threats of the P2PInfect botnet and learn how to recognize and avoid malicious activities. With user training, a more comprehensive protection against the P2PInfect botnet can be achieved.
Source: bleepingcomputer
