Redis Cryptomining Botnet Compromised 3,562 Servers, Revealed by Operator’s Exposed Files

· Original article ↗

Summary

Analysis of an exposed operator directory and campaign logs found 3,562 Redis servers compromised through unauthenticated rogue replication and used to run XMRig for Monero mining.

Key points

  • The report attributes 3,562 distinct Redis compromises to two campaign runs against a shared list of 12,966 hosts.
  • The main attack abused Redis rogue replication (SLAVEOF/RDB) to write cron persistence and deploy XMRig; it did not rely on a version-specific vulnerability.
  • Confirmed victims ran Redis 2.8.17 through 7.2.0, indicating that missing authentication or other insecure deployment settings—not a particular Redis version—enabled the attacks.
  • A third run against 2,342 pre-qualified unauthenticated hosts succeeded against 72.6%, compared with 22–26% across the larger, less-current target list.
  • SSH key injection and MongoDB sandbox-escape attempts produced no confirmed compromises; a WordPress credential-to-webshell chain was recovered, but its campaign-scale impact could not be quantified.
  • The compromised servers downloaded XMRig and mined Monero; the exposed files also revealed the operator’s infrastructure, tooling, and a separate earlier mining toolkit linked by wallet reuse.
  • The report recommends restricting Redis exposure, requiring authentication, disabling unused replication commands, and checking for suspicious persistence files and outbound connections.

Article Details

Attack Vectors
  • The primary campaign targeted internet-facing Redis servers that accepted commands without authentication. Rogue replication delivered a crafted RDB file into cron persistence paths; 3,562 distinct servers were confirmed compromised across two full-fleet runs.
  • An AOF-based attempt to write SSH authorized_keys files produced no confirmed key injection or SSH login across 2,342 targets; nearly all attempts stopped at an AUTH_REQUIRED response.
  • Redis Lua sandbox-escape probing was observed on three test hosts, with no fleet-scale deployment shown. MongoDB server-side JavaScript escape probing produced no confirmed escape across 468 scriptable hosts.
  • A separate WordPress track combined username enumeration, credential spraying, default-credential login attempts, nonce harvesting, and PHP webshell staging. The recovered files do not establish its campaign-scale impact.
  • Recovered QA-only tooling tested additional persistence paths, including APT hooks, profile.d scripts, SysV init directories, and /etc/modprobe.d; the report does not show those mechanisms deployed across the production fleet.
Defensive Notes
  • Do not expose Redis to untrusted networks without authentication. Where replication is unnecessary, restrict SLAVEOF/REPLICAOF or use protected mode; upgrading Redis alone does not address the configuration weakness described.
  • Inspect cron locations, APT hooks, profile.d, SSH authorized_keys files, and Redis dir/dbfilename settings for the reported persistence and file-write behavior.
  • Monitor affected hosts for C2 HTTP check-ins, mining-pool connections, and hidden miner files under /tmp.
  • For WordPress, enforce strong unique administrator passwords, disable XML-RPC where unnecessary, and investigate repeated login attempts, unexpected plugin installations, and PHP webshells.
  • For MongoDB, disable server-side scripting where it is unnecessary.

Indicators of compromise

TypeIndicatorContext
DOMAINpool[.]moneroocean[.]streamPublic mining pool used by XMRig deployed to compromised Redis servers; not identified as operator-controlled.
DOMAINxmr[.]pool[.]minergate[.]comMining pool endpoint specified in early miner deployers in the operator-linked February directory.
HOSTNAMEsocket[.]ayakliborsa[.]netHostname the report assesses as live operator-controlled infrastructure resolving to the rogue Redis and C2 host.
IPV4188[.]245[.]99[.]156Operator host used for rogue Redis replication, C2 check-ins, and payload staging.
IPV4194[.]48[.]248[.]105Host of an earlier malicious open directory containing Meterpreter and miner deployers, linked to the later toolkit by wallet reuse.
IPV445[.]155[.]102[.]89Mining pool or proxy endpoint used by the operator's local miner; the report assesses it as likely private.

MITRE ATT&CK

Vendors

Products

Tools

Countries

Industries

Related Articles