hunt.io Massive Redis Cryptomining Botnet Compromises 3,562 Servers
Article Content
- •3,562 Redis servers compromised due to missing authentication.
- •Attack exploited CVE-2024-21762 against a Thai broadband provider's SSL-VPN.
- •Operator's toolkit was exposed, revealing extensive attack methods.
A cryptomining botnet has compromised 3,562 Redis servers, primarily due to missing authentication. The attack targeted a shared list of 12,966 hosts, with a significant success rate of 22-26%. The compromised servers span Redis versions from 2.8.17 to 7.2.0 and various Linux distributions, indicating a lack of security measures rather than specific vulnerabilities. The botnet's operator inadvertently exposed their toolkit, which included Python exploits and campaign logs. Additionally, a Thai broadband provider was targeted through a FortiGate SSL-VPN vulnerability (CVE-2024-21762), with evidence of persistent backdoor access via MeshCentral. The attack's infrastructure was discovered on June 3, 2026, and the threat actor had knowledge of organization-specific credentials. The situation remains critical as the botnet continues to exploit vulnerable Redis servers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track XMRig, Jasmine International and CVE-2018-13379 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Human Attacker Exploits Marimo RCE at Machine Speed A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven…