Redis Cryptomining Botnet Compromised 3,562 Servers, Revealed by Operator’s Exposed Files

Summary
Analysis of an exposed operator directory and campaign logs found 3,562 Redis servers compromised through unauthenticated rogue replication and used to run XMRig for Monero mining.
Key points
- The report attributes 3,562 distinct Redis compromises to two campaign runs against a shared list of 12,966 hosts.
- The main attack abused Redis rogue replication (SLAVEOF/RDB) to write cron persistence and deploy XMRig; it did not rely on a version-specific vulnerability.
- Confirmed victims ran Redis 2.8.17 through 7.2.0, indicating that missing authentication or other insecure deployment settings—not a particular Redis version—enabled the attacks.
- A third run against 2,342 pre-qualified unauthenticated hosts succeeded against 72.6%, compared with 22–26% across the larger, less-current target list.
- SSH key injection and MongoDB sandbox-escape attempts produced no confirmed compromises; a WordPress credential-to-webshell chain was recovered, but its campaign-scale impact could not be quantified.
- The compromised servers downloaded XMRig and mined Monero; the exposed files also revealed the operator’s infrastructure, tooling, and a separate earlier mining toolkit linked by wallet reuse.
- The report recommends restricting Redis exposure, requiring authentication, disabling unused replication commands, and checking for suspicious persistence files and outbound connections.
Article Details
- Attack Vectors
- The primary campaign targeted internet-facing Redis servers that accepted commands without authentication. Rogue replication delivered a crafted RDB file into cron persistence paths; 3,562 distinct servers were confirmed compromised across two full-fleet runs.
- An AOF-based attempt to write SSH authorized_keys files produced no confirmed key injection or SSH login across 2,342 targets; nearly all attempts stopped at an AUTH_REQUIRED response.
- Redis Lua sandbox-escape probing was observed on three test hosts, with no fleet-scale deployment shown. MongoDB server-side JavaScript escape probing produced no confirmed escape across 468 scriptable hosts.
- A separate WordPress track combined username enumeration, credential spraying, default-credential login attempts, nonce harvesting, and PHP webshell staging. The recovered files do not establish its campaign-scale impact.
- Recovered QA-only tooling tested additional persistence paths, including APT hooks, profile.d scripts, SysV init directories, and /etc/modprobe.d; the report does not show those mechanisms deployed across the production fleet.
- Defensive Notes
- Do not expose Redis to untrusted networks without authentication. Where replication is unnecessary, restrict SLAVEOF/REPLICAOF or use protected mode; upgrading Redis alone does not address the configuration weakness described.
- Inspect cron locations, APT hooks, profile.d, SSH authorized_keys files, and Redis dir/dbfilename settings for the reported persistence and file-write behavior.
- Monitor affected hosts for C2 HTTP check-ins, mining-pool connections, and hidden miner files under /tmp.
- For WordPress, enforce strong unique administrator passwords, disable XML-RPC where unnecessary, and investigate repeated login attempts, unexpected plugin installations, and PHP webshells.
- For MongoDB, disable server-side scripting where it is unnecessary.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | pool[.]moneroocean[.]stream | Public mining pool used by XMRig deployed to compromised Redis servers; not identified as operator-controlled. |
| DOMAIN | xmr[.]pool[.]minergate[.]com | Mining pool endpoint specified in early miner deployers in the operator-linked February directory. |
| HOSTNAME | socket[.]ayakliborsa[.]net | Hostname the report assesses as live operator-controlled infrastructure resolving to the rogue Redis and C2 host. |
| IPV4 | 188[.]245[.]99[.]156 | Operator host used for rogue Redis replication, C2 check-ins, and payload staging. |
| IPV4 | 194[.]48[.]248[.]105 | Host of an earlier malicious open directory containing Meterpreter and miner deployers, linked to the later toolkit by wallet reuse. |
| IPV4 | 45[.]155[.]102[.]89 | Mining pool or proxy endpoint used by the operator's local miner; the report assesses it as likely private. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationRecovered loaders used base64-encoded Python, while WordPress and log-processing scripts encoded string literals as chr() calls.T1053.003 · CronRogue Redis replication wrote miner-deployment cron entries to victim hosts; recovered QA tooling also tested cron persistence.T1071.001 · Web ProtocolsA persistence command sent plain HTTP GET heartbeat requests from compromised hosts to the operator's C2 service.T1098.004 · SSH Authorized KeysRecovered Redis tooling was designed to write an SSH public key into authorized_keys and verify login, but the campaign log showed no successful injection.T1105 · Ingress Tool TransferVictim-side deployment commands used curl to download an XMRig release archive before installing and running the miner.T1110.003 · Password SprayingThe WordPress script tried username and password pairs across scanned sites through XML-RPC, with a login-form fallback.T1496 · Resource HijackingThe cron payload downloaded and ran XMRig on compromised Redis servers to mine using the operator's wallet.T1505.003 · Web ShellA one-line PHP webshell was recovered alongside WordPress plugin-install takeover tooling; installation on a target was not confirmed.T1564.001 · Hidden Files and DirectoriesThe deployment command renamed the XMRig executable to the dot-prefixed file /tmp/.xmrig.
Vendors
Hetzner Online GmbH188.245[.]99.156 is a Hetzner dedicated server, not throwaway bulletproof hosting. ASN AS24940 (Hetzner Online GmbH, Nuremberg, Germany), standard your-server.de PTR, no TOR, proxy, or VPN flags. This is a rentedOvO Systems Ltd.other two point somewhere we hadn't seen: 194.48.248[.]105:8081 (AS200019, currently registered to OvO Systems Ltd., Chisinau, Moldova), first indexed 2026-02-23, about four months before the Redis toolkit surfaced
Products
breezeare exposed. The plugin data goes deeper than a simple detection flag, one confirmed site running the breeze caching plugin at version 2.5.6 is marked "vulnerable": false, which only makes sense if the scanner isMongoDBacross three services, but only Redis rogue replication worked at scale: SSH key-injection and MongoDB sandbox-escape returned zero across 2,810 attempts, and a complete WordPress credential-to-webshell chainRedisDirectly parsing the operator's own campaign logs shows 3,562 distinct Redis servers compromised across two runs against a shared 12,966-host list; 22 to 26% of targets were compromised and most of the rest blocked onWordPressscale: SSH key-injection and MongoDB sandbox-escape returned zero across 2,810 attempts, and a complete WordPress credential-to-webshell chain was recovered but not confirmed at scale.
Tools
AttackCapturefour months earlier, on different infrastructure, run by the same wallet holder. Searching Hunt.io's AttackCapture corpus for the exact Monero wallet string hardcoded throughout this toolkit returns eleven hits. Nineccminerdeploy_miner.sh, deploy_miner_real_v2.shEarly generation: downloads ccminer, points at xmr.pool.minergate.com:45700Meterpreterthe toolkit also appears in a separate February 2026 open directory at 194.48.248[.]105 (Moldova), a Meterpreter and XMRig kit with no Redis component, pushing the operator's known activity back at least five months.XMRigalso appears in a separate February 2026 open directory at 194.48.248[.]105 (Moldova), a Meterpreter and XMRig kit with no Redis component, pushing the operator's known activity back at least five months.
Countries
China39.101[.]x.x: a readable SQL database dump on a WordPress site (China, logistics sector)Germany173.212[.]x.x: a readable SQL database dump on a WordPress site (Germany)Moldovathroughout the toolkit also appears in a separate February 2026 open directory at 194.48.248[.]105 (Moldova), a Meterpreter and XMRig kit with no Redis component, pushing the operator's known activity back at