Skip to content

P2PInfect

P2PInfect is a Rust-written, self-propagating malware family and decentralized peer-to-peer worm/botnet first observed in mid-2023.

Profile source: Mallory opens in a new tab

P2PInfect

Family profile

P2PInfect is a Rust-written, self-propagating malware family and decentralized peer-to-peer worm/botnet first observed in mid-2023. It primarily targets Redis instances exposed to the internet, including unauthenticated or vulnerable deployments, and has also been observed compromising Kubernetes environments, including Google Kubernetes Engine (GKE) clusters. Reported Redis tradecraft includes abuse of misconfigured replication via the SLAVEOF command and exploitation of CVE-2022-0543; FortiGuard also linked some P2PInfect activity to exploitation of CVE-2025-11953 (Metro4Shell) against React Native Metro servers, and assessed with low confidence that CVE-2025-49844 (RediShell) may also have been incorporated as an access vector.

The malware uses a resilient P2P mesh rather than centralized C2, with peer communications over non-standard ports and bootstrap node lists embedded in malware arguments. Payload delivery has been observed via uniform peer-hosted paths such as /Linux, /Windows, and /IP. Recovered samples in the cited cluster were Rust binaries generally packed with UPX. A FortiGuard-observed deployment script, deployer.sh/deplyoer.sh (MD5: 80676a539765a9e117f20b6b99887eca), downloaded a Linux x86_64 client from http://8[.]210[.]50[.]65:60126/linux, wrote it to /top/RarF51vUe0, and dropped a sample with MD5 5d1ca537c4bedebf2f4d276d4199ea95. Additional reported sample hashes include Linux client MD5 a1a35afebb585917675534de3d610c93 and Windows client MD5 08ad2c2877edda9a050b81d011c1c003. FortiGuard reported the malware processed a base64 argument blob with ChaCha20 using an all-zero key and nonce, serving as obfuscation, and that decrypted data contained structured bootstrap peer IP:port records.

Operationally, P2PInfect has shown long-lived persistence: FortiGuard documented infections in GKE clusters at several client companies, including one compromise lasting six months, with no second-stage payload executed in the monitored environments. The malware has been described as capable of remaining dormant for extended periods before later delivery of ransomware and cryptominers, and some variants reportedly include usermode rootkit capabilities. Reporting also states there is evidence P2PInfect may function as a botnet-for-hire platform where other actors deploy their own second-stage payloads.

Observed follow-on activity associated with P2PInfect includes deployment of Monero cryptominers and ransomware on internet-exposed, unpatched Redis servers. Separate reporting on Linux SSH honeypot activity found P2PInfect to be the dominant attack source in Q1 2026, accounting for 70.3% of observed attack sources, and noted that the malware also includes a basic SSH password sprayer. Targeted environments explicitly mentioned in the content include Linux systems, Windows systems, Redis servers, React Native Metro servers, Kubernetes clusters, and cloud-hosted GKE environments.

Observed infrastructure

Last seven days

First activity
Aug 11, 2026
Last activity
Aug 11, 2026
Feed role
Distribution
Host form
26 IP / 0 hostnames

Leading locations

  • SG20
  • CN4
  • DE1
  • GB1

Leading providers

  • Alibaba (US) Technology Co., Ltd.20
  • Amazon.com, Inc.1
  • Beijing Baidu Netcom Science and Technology Co., Ltd.1
  • China Telecom (Group)1
  • DigitalOcean, LLC1
  • Shenzhen Tencent Computer Systems Company Limited1

Infrastructure traits

  • Hosting 25

Exploited software

Vulnerabilities linked to P2PInfect

3 CVEs

MITRE ATT&CK

P2PInfect in ATT&CK

22 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.