Skip to content
ThreatCluster

Over 3,500 Redis Servers Compromised for Cryptocurrency Mining

First seen 11 Sep 2026, 01:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 02:17 UTC
  • 3,562 Redis servers compromised for cryptocurrency mining.
  • Attackers exploited lack of authentication on internet-facing Redis instances.
  • No specific CVE exists; the issue is due to misconfiguration.

A large-scale cyber operation has compromised 3,562 internet-exposed Redis servers, exploiting their lack of authentication to convert them into cryptocurrency miners. The attackers targeted a total of 12,966 Redis instances, successfully taking over 22-26% of them using rogue replication techniques. The compromised servers ran various Redis versions from 2.8.17 to 7.2.0 on Linux systems. The attack involved injecting malicious code via the SLAVEOF/replicaof command and subsequently using cron jobs to execute XMRig, a Monero mining software. Hunt.io's analysis revealed that there is no specific CVE for this issue, as the vulnerability stems from poor configuration rather than software flaws. The campaign has been active since at least February 2026, with the operator's tools still in use as of June 2026. Security experts recommend that administrators secure their Redis instances by implementing authentication and restricting network exposure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-02-01
Initial attack observed
Attackers began targeting Redis servers with no authentication, leading to compromises.
exploitbulletin.com
2026-06-30
Operator's tools still active
Hunt.io confirmed the continued use of the attacker's tooling for Redis exploitation.
exploitbulletin.com
2026-09-09
Cybersecurity news coverage
Cybersecuritynews reported on the ongoing campaign affecting Redis servers.
Cybersecuritynews
2026-09-11
Exploit bulletin published
Exploit bulletin provided detailed analysis of the Redis server compromises and attack methods.
exploitbulletin.com

More articles in this cluster (2)

Following this threat?

Track XMRig and Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed