3,500 Redis Servers Hijacked for Cryptocurrency Mining Operation
A large-scale cryptomining operation has compromised over 3,500 Redis servers, turning their processing power into a source of Monero revenue. The campaign targeted internet-facing Redis instances that accepted commands without authentication.
The attackers scanned 12,966 potential targets and used Redis replication features to plant a scheduled task that downloaded and ran a miner. This approach can make the traffic look less unusual than mining on a dedicated port.
Researchers at Hunters.io identified the campaign after finding an exposed directory containing 147 files, including exploit code and campaign logs. The logs show two large runs compromised 3,388 and 2,862 hosts respectively, with overlap between them.