Last seven days
- First activity
- Aug 11, 2026
- Last activity
- Aug 11, 2026
- Feed role
- Distribution
- Host form
- 26 IP / 0 hostnames
P2PInfect is a Rust-written, self-propagating malware family and decentralized peer-to-peer worm/botnet first observed in mid-2023.
Profile source: Mallory opens in a new tabP2PInfect
P2PInfect is a Rust-written, self-propagating malware family and decentralized peer-to-peer worm/botnet first observed in mid-2023. It primarily targets Redis instances exposed to the internet, including unauthenticated or vulnerable deployments, and has also been observed compromising Kubernetes environments, including Google Kubernetes Engine (GKE) clusters. Reported Redis tradecraft includes abuse of misconfigured replication via the SLAVEOF command and exploitation of CVE-2022-0543; FortiGuard also linked some P2PInfect activity to exploitation of CVE-2025-11953 (Metro4Shell) against React Native Metro servers, and assessed with low confidence that CVE-2025-49844 (RediShell) may also have been incorporated as an access vector.
The malware uses a resilient P2P mesh rather than centralized C2, with peer communications over non-standard ports and bootstrap node lists embedded in malware arguments. Payload delivery has been observed via uniform peer-hosted paths such as /Linux, /Windows, and /IP. Recovered samples in the cited cluster were Rust binaries generally packed with UPX. A FortiGuard-observed deployment script, deployer.sh/deplyoer.sh (MD5: 80676a539765a9e117f20b6b99887eca), downloaded a Linux x86_64 client from http://8[.]210[.]50[.]65:60126/linux, wrote it to /top/RarF51vUe0, and dropped a sample with MD5 5d1ca537c4bedebf2f4d276d4199ea95. Additional reported sample hashes include Linux client MD5 a1a35afebb585917675534de3d610c93 and Windows client MD5 08ad2c2877edda9a050b81d011c1c003. FortiGuard reported the malware processed a base64 argument blob with ChaCha20 using an all-zero key and nonce, serving as obfuscation, and that decrypted data contained structured bootstrap peer IP:port records.
Operationally, P2PInfect has shown long-lived persistence: FortiGuard documented infections in GKE clusters at several client companies, including one compromise lasting six months, with no second-stage payload executed in the monitored environments. The malware has been described as capable of remaining dormant for extended periods before later delivery of ransomware and cryptominers, and some variants reportedly include usermode rootkit capabilities. Reporting also states there is evidence P2PInfect may function as a botnet-for-hire platform where other actors deploy their own second-stage payloads.
Observed follow-on activity associated with P2PInfect includes deployment of Monero cryptominers and ransomware on internet-exposed, unpatched Redis servers. Separate reporting on Linux SSH honeypot activity found P2PInfect to be the dominant attack source in Q1 2026, accounting for 70.3% of observed attack sources, and noted that the malware also includes a basic SSH password sprayer. Targeted environments explicitly mentioned in the content include Linux systems, Windows systems, Redis servers, React Native Metro servers, Kubernetes clusters, and cloud-hosted GKE environments.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.