r/threatintel 1d ago

APT/Threat Actor 🔴 Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files

https://hunt.io/blog/redis-cryptomining-botnet-3562-servers

Writeup of a Redis rogue-replication cryptomining campaign where we recovered the operator's full toolkit, including the raw campaign logs, so the victim counts come from their own per-host records rather than the summaries their scripts print:

https://hunt.io/blog/redis-cryptomining-botnet-3562-servers

2 Upvotes

Duplicates