P2PInfect , a peer-to-peer malware botnet, has developed a new ransomware module and a cryptominer to carry out attacks on Redis servers.

According to Cado Security, which monitors P2PInfect, there are indications that the malware operates as a “botnet for hire,” although it is not easy to draw precise conclusions at this time.
P2PInfect botnet
P2PInfect was first detected and analyzed in July 2023 by researchers at Unit 42. It targeted Redis servers using known security.
Later, Cado Security studied the botnet malware and revealed that a Redis replication feature to spread it.
Between August and September 2023, increased P2PInfect activity was observed, while new useful features were introduced, such as persistence mechanisms, alternative communication systems, and SSH lockout. However, despite the increased activity, the P2PInfect botnet did not perform any malicious actions on the compromised systems. For this reason, researchers are unsure of the attackers' motives.
See also: Muhstik botnet exploits vulnerability in Apache RocketMQ
In December 2023, a new variant of P2PInfect was discovered by analysts at Cado, which was designed to target 32-bit MIPS (Microprocessor Without Interlocked Pipelined Stage) processors found in routers and IoT devices.
P2PInfect botnet: New ransomware, cryptominer modules, unclear targets
Cado reports that as of May 16, 2024, devices infected with P2PInfect received a command to download and execute a ransomware payload (rsagen) from a specified URL.
Upon startup, the ransomware binary checks for the presence of a ransom note (“Your data has been locked!.txt”) to avoid re-encrypting compromised systems.
The ransomware targets files with specific extensions related to databases (SQL, SQLITE3, DB), documents (DOC, XLS), and multimedia files (MP3, WAV, MKV) and adds the “.encrypted” extension to the resulting files.
The ransomware spreads across directories, encrypting files and storing a database of encrypted files in a temporary file with the extension “.lockedfiles”.
See also: Pumpkin Eclipse Botnet destroyed 600,000 routers
The second new module, the XMR (Monero) miner, is installed in a temporary directory and launched five minutes after the main payload is launched.
The preconfigured wallet and mining pool in the samples examined has 71 XMR so far, which is about $10,000, but researchers say that the operators of the P2PInfect botnet may be using additional wallet addresses.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A special feature of the new P2PInfect is that the miner is configured to use all available processing power, often interfering with the operation of the ransomware module.

Additionally, there is a new user-mode rootkit that allows P2PInfect bots to hide their malicious processes and files from security tools by infecting multiple processes.
Cado Security's research clearly shows that the P2PInfect botnet poses a real threat to Redis servers, with its new ransomware and cryptominer modules.
Protection against botnet malware
To protect yourself from P2PInfect and other Botnets, it is important to keep your device's software and operating system up to date. Botnet attacks often exploit known vulnerabilities.
Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.
See also: US government imposes sanctions on 911 S5 botnet hackers
Using strong passwords and changing them regularly is another way to protect yourself from Botnets (e.g. P2PInfect). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect accounts .
Finally, information security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.
Source: www.bleepingcomputer.com
