HomeSecurityNew Migo malware targets Redis servers for cryptomining

New Migo malware targets Redis servers for cryptomining

Security researchers have discovered a new malicious campaign targeting Redis servers on Linux systems, using a new malware called “Migo.” The goal is cryptomining.

Migo malware

Redis (Remote Dictionary Server) is used as a database ,cache, and message broker. It stands out for its high performance, serving thousands of requests per second for real-time applications and is used in industries such as gaming, technology, financial services, and healthcare.

Redis servers are often targeted by hackers who want to steal resources and data, as well as carry out other malicious activities.

The new Migo malware used to target Redis servers stands out for its use of system weakening commands , which disable Redis features security , allowing cryptomining

See also: Ukrainian administrator of Raccoon Infostealer Malware arrested

The Migo malware attacks were detected by analysts at Cado Security, who observed that the attackers were using CLI commands on their honeypots to disable protection measures and exploit the server.

When compromising exposed Redis servers, attackers disable critical security, allowing for execution of subsequent commands and other malicious activities.

Specifically, according to the researchers, the following configuration options were disabled:

set protected-mode: disabling allows external access to the Redis server, making it easier to execute commands remotely.

Replica-read-only: disabling allows attackers to write directly to replicas and propagate malicious payloads or data modifications.

aof-rewrite-incremental-fsync: disabling helps attackers remain undetected by distracting detection tools with unusual IO patterns.

rdb-save-incremental-fsync: disabling it may cause performance degradation when saving RDB snapshots, allowing attackers to cause a denial of service (DoS).

Researchers say the hackers then create a cron job that downloads a script from Pastebin. This brings the main Migo malware (/tmp/.migo) from Transfer.sh to run as a background task.

See also: PDF documents are increasingly used to distribute malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cado says that the main function of the Migo malware on Redis servers is to retrieve, install, and launch a modified XMRig (Monero) miner on the compromised endpoint for cryptomining.

The malware creates persistence for the miner by creating a systemd service and associated timer. It ensures that the miner runs continuously, mining cryptocurrencies on behalf of the attacker.

Cado reports that the Migo malware uses a user-mode rootkit to hide its processes and files, complicating detection and removal.

Redis servers for cryptomining

The malware modifies “/etc/ld.so.preload” to interfere and change the behavior of system tools that list processes and files, effectively hiding its presence.

The attack is completed by creating firewall rules to block outbound traffic to certain IPs and executing commands to disable SELinux. It also searches for and possibly disables cloud provider monitoring agents and removes competing miners or payloads.

The above shows that protection against cryptomining is essential, as this practice is becoming increasingly common. Cryptomining has the potential to exploit your device's resources, exposing you to many risks. But don't worry, there are some ways to protect yourself. 

See also: SNS Sender Malware distributes Phishing SMS via Amazon

First, you should keep your device software up to date. Security updates help fix security holes that could be exploited by cybercriminals targeting cryptomining.

Next, use antivirus and intrusion detection programs. Consider using special programs or extensions to prevent cryptomining from taking place on your device. These types of tools can identify and block cryptomining scripts running in web browser . 

Finally, it is important to be careful with the sites you visit and the files you download.

With cryptomining protection, you can continue to use the internet safely. Always remember, knowledge is power – learn about the potential risks and how to deal with them.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS