Cryptomining
"Hydra Bot v5": A Redis Stager Designed to Deploy a P2PInfect Client and Miner
Analysis of an in-the-wild Redis deployment chain: artifacts for four known Redis abuse patterns delivered in 4.4 seconds, a stager not found in public datasets designed to deploy a P2PInfect-linked ELF and an apparent miner, and campaign infrastructure exposed through a hostname guard.
SuricataYARASigmaIOC 17 min readPrometei Goes Both Ways: Same C2, Both Operating Systems, Three Months Apart [1/2]
A fresh Prometei v3/v4 ELF on a Linux honeypot, beaconing to the same C2 IP, Tor onion, and UPlugPlay disguise convention eSentire flagged on the Windows side three months earlier. The JSON-trailer schema yields a parent-peer back-pointer per bot. Postscript: four parallel binary-churn cadences in the same toolkit, including bit-identical zsvc unpacked code across drops.
IOC 22 min readTurf Wars at Scale: Botnets Fighting for the Same Servers
42 post-auth payload deployments from 13 coordinated IPs on AS51396 over 58 hours. The eviction script that precedes each install maps the contested-infrastructure reality: Diicot self-eviction, XMRig, CNRig, Rete, and Kinsing artifacts competing on the same pools of exposed servers.
IOC 12 min read