Over 3,500 Redis Servers Compromised for Cryptocurrency Mining
Article Content
- •3,562 Redis servers compromised for cryptocurrency mining.
- •Attackers exploited lack of authentication on internet-facing Redis instances.
- •No specific CVE exists; the issue is due to misconfiguration.
A large-scale cyber operation has compromised 3,562 internet-exposed Redis servers, exploiting their lack of authentication to convert them into cryptocurrency miners. The attackers targeted a total of 12,966 Redis instances, successfully taking over 22-26% of them using rogue replication techniques. The compromised servers ran various Redis versions from 2.8.17 to 7.2.0 on Linux systems. The attack involved injecting malicious code via the SLAVEOF/replicaof command and subsequently using cron jobs to execute XMRig, a Monero mining software. Hunt.io's analysis revealed that there is no specific CVE for this issue, as the vulnerability stems from poor configuration rather than software flaws. The campaign has been active since at least February 2026, with the operator's tools still in use as of June 2026. Security experts recommend that administrators secure their Redis instances by implementing authentication and restricting network exposure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track XMRig and Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
BengalSEO Campaign Delivers Malware via SEO Poisoning In March 2026, a significant SEO poisoning campaign named BengalSEO was identified, attributed to two IT service providers in Rajasthan, India. This operation has been active since at least 2015, utilizing Black Hat SEO techniques to create lure pages that redirect users to tech support scams and malware deployment.…