Redis 2 published
Redis
"Hydra Bot v5": A Redis Stager Designed to Deploy a P2PInfect Client and Miner
Analysis of an in-the-wild Redis deployment chain: artifacts for four known Redis abuse patterns delivered in 4.4 seconds, a stager not found in public datasets designed to deploy a P2PInfect-linked ELF and an apparent miner, and campaign infrastructure exposed through a hostname guard.
SuricataYARASigmaIOC 17 min readTwo-Way Prometei: When the Linux Botnet Pivots Back to Windows [2/2]
17 Windows modules dropped alongside the Linux ELF in the same Prometei drop, including a Mimikatz variant frozen since 2023, a Tor stack masquerading as MSDTC and Smart Card services, and a Linux ELF that pivots back to Windows via WinRM (5985), Redis SLAVEOF (16379), and SMBv1-era dialects. One cross-platform toolkit, walker.ini glue, server-side fingerprint of the C2.
IOC 20 min read