HomeSecurityP2PInfect botnet: Targets Redis servers with new ransomware and cryptominer modules

P2PInfect botnet: Targets Redis servers with new ransomware and cryptominer modules

P2PInfect , a peer-to-peer malware botnet, has developed a new ransomware module and a cryptominer to carry out attacks on Redis servers.

P2PInfect botnet ransomware and cryptominer

According to Cado Security, which monitors P2PInfect, there are indications that the malware operates as a “botnet for hire,” although it is not easy to draw precise conclusions at this time.

P2PInfect botnet

P2PInfect was first detected and analyzed in July 2023 by researchers at Unit 42. It targeted Redis servers using known security.

Later, Cado Security studied the botnet malware and revealed that a Redis replication feature to spread it.

Between August and September 2023, increased P2PInfect activity was observed, while new useful features were introduced, such as persistence mechanisms, alternative communication systems, and SSH lockout. However, despite the increased activity, the P2PInfect botnet did not perform any malicious actions on the compromised systems. For this reason, researchers are unsure of the attackers' motives.

See also: Muhstik botnet exploits vulnerability in Apache RocketMQ

In December 2023, a new variant of P2PInfect was discovered by analysts at Cado, which was designed to target 32-bit MIPS (Microprocessor Without Interlocked Pipelined Stage) processors found in routers and IoT devices.

P2PInfect botnet: New ransomware, cryptominer modules, unclear targets

Cado reports that as of May 16, 2024, devices infected with P2PInfect received a command to download and execute a ransomware payload (rsagen) from a specified URL.

Upon startup, the ransomware binary checks for the presence of a ransom note (“Your data has been locked!.txt”) to avoid re-encrypting compromised systems.

The ransomware targets files with specific extensions related to databases (SQL, SQLITE3, DB), documents (DOC, XLS), and multimedia files (MP3, WAV, MKV) and adds the “.encrypted” extension to the resulting files.

The ransomware spreads across directories, encrypting files and storing a database of encrypted files in a temporary file with the extension “.lockedfiles”.

See also: Pumpkin Eclipse Botnet destroyed 600,000 routers

The second new module, the XMR (Monero) miner, is installed in a temporary directory and launched five minutes after the main payload is launched.

The preconfigured wallet and mining pool in the samples examined has 71 XMR so far, which is about $10,000, but researchers say that the operators of the P2PInfect botnet may be using additional wallet addresses.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A special feature of the new P2PInfect is that the miner is configured to use all available processing power, often interfering with the operation of the ransomware module.

Redis servers

Additionally, there is a new user-mode rootkit that allows P2PInfect bots to hide their malicious processes and files from security tools by infecting multiple processes.

Cado Security's research clearly shows that the P2PInfect botnet poses a real threat to Redis servers, with its new ransomware and cryptominer modules.

Protection against botnet malware

To protect yourself from P2PInfect and other Botnets, it is important to keep your device's software and operating system up to date. Botnet attacks often exploit known vulnerabilities.

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

See also: US government imposes sanctions on 911 S5 botnet hackers

Using strong passwords and changing them regularly is another way to protect yourself from Botnets (e.g. P2PInfect). Botnet attacks often try to guess passwords, so using strong passwords and changing them regularly can help protect accounts .

Finally, information security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS