P2PInfect
P2PInfect is a Rust-based peer-to-peer worm and botnet malware family first observed in 2023 that primarily targets exposed or vulnerable Redis deployments and has also been observed propagating via SSH password attacks.
Profile source: Mallory opens in a new tabP2PInfect
Family profile
P2PInfect is a Rust-based peer-to-peer worm and botnet malware family first observed in 2023 that primarily targets exposed or vulnerable Redis deployments and has also been observed propagating via SSH password attacks. Its decentralized architecture allows infected nodes to exchange peer lists, distribute updated binaries, and continue operating without a centralized command-and-control server, increasing resilience against sinkholing and takedown efforts. The malware supports cross-platform operation, with confirmed Linux and Windows payloads and reported variants for additional CPU architectures including ARM and MIPS.
A well-documented initial access path is exploitation of CVE-2022-0543 against Debian-derived Redis deployments. P2PInfect has also been associated with abuse of misconfigured Redis replication features and with brute-force or password-spraying activity against SSH services. More recent reporting links parts of the botnet ecosystem to exploitation of CVE-2025-11953 against React Native Metro servers, indicating expansion beyond Redis-centric propagation. Use of CVE-2025-49844 has been discussed only at low confidence and should not be treated as confirmed.
After compromise, P2PInfect enrolls hosts into a P2P mesh, scans for additional Redis and SSH targets, and can retrieve additional modules for follow-on activity. Observed tooling and module naming indicate support for delivery of cryptominers and Windows-specific payloads, and the botnet has been linked in the wild to later-stage deployment of ransomware and cryptocurrency mining. In some environments the malware has remained dormant for extended periods after initial enrollment, suggesting an infrastructure-building or botnet-for-hire model in which access may later be monetized through second-stage payload delivery.
The malware includes multiple defense-evasion and resilience features. Reported behaviors include UPX packing, anti-debugging measures, disabling core dumps, self-updating components, runtime modification of an auxiliary executable, wrapper binaries used to disguise the main payload, and Windows persistence-related behavior involving a monitor process and firewall rule changes. Some variants have also been described as having user-mode rootkit capabilities.
P2PInfect has been observed targeting internet-exposed servers and cloud environments, including compromises within Kubernetes clusters through exposed Redis services. Activity has been reported across enterprise and cloud-hosted infrastructure rather than being limited to a single industry vertical. The combination of worm-like propagation, decentralized botnet control, cross-platform support, and modular payload delivery makes P2PInfect a durable threat to poorly secured Redis and SSH-exposed systems.
Capabilities
- Brute Force
- Ddos
- Defense Evasion
- Exfiltration
- Extortion
- Initial Access
- Persistence
- Scanning
Exploited software
Vulnerabilities linked to P2PInfect
3 CVEsMITRE ATT&CK