Skip to content
Massive Redis Cryptomining Botnet Compromises 3,562 Servers

Massive Redis Cryptomining Botnet Compromises 3,562 Servers

First seen 15 Sep 2026, 12:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 13:53 UTC
  • 3,562 Redis servers compromised due to missing authentication.
  • Attack exploited CVE-2024-21762 against a Thai broadband provider's SSL-VPN.
  • Operator's toolkit was exposed, revealing extensive attack methods.

A cryptomining botnet has compromised 3,562 Redis servers, primarily due to missing authentication. The attack targeted a shared list of 12,966 hosts, with a significant success rate of 22-26%. The compromised servers span Redis versions from 2.8.17 to 7.2.0 and various Linux distributions, indicating a lack of security measures rather than specific vulnerabilities. The botnet's operator inadvertently exposed their toolkit, which included Python exploits and campaign logs. Additionally, a Thai broadband provider was targeted through a FortiGate SSL-VPN vulnerability (CVE-2024-21762), with evidence of persistent backdoor access via MeshCentral. The attack's infrastructure was discovered on June 3, 2026, and the threat actor had knowledge of organization-specific credentials. The situation remains critical as the botnet continues to exploit vulnerable Redis servers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-06-04
CVE-2018-13379 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-02-21
Public exploit for CVE-2020-1938 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2021-03-17
Public exploit for CVE-2021-22986 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2022-05-05
CVE-2022-1388 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-12-13
CVE-2022-42475 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2023-06-13
CVE-2023-27997 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-26
CVE-2023-46747 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-09
CVE-2024-21762 published
CVE-2024-21762 was published, detailing a vulnerability in FortiGate SSL-VPN exploited in the attacks.
hunt.io
2026-06-03
Open directory discovered
Hunt.io's AttackCapture found an open directory containing exploitation tools targeting 3BB.
hunt.io
2026-06-21
Directory indexed by Hunt.io
Hunt.io first indexed the operator's directory containing their entire working toolkit.
hunt.io

More articles in this cluster (2)

Following this threat?

Track XMRig, Jasmine International and CVE-2018-13379 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed