P2PInfect
P2PInfect is a Rust-based, cross-platform peer-to-peer worm and decentralized botnet active since at least 2023.
Profile source: Mallory opens in a new tabP2PInfect
Family profile
P2PInfect is a Rust-based, cross-platform peer-to-peer worm and decentralized botnet active since at least 2023. It primarily compromises exposed or vulnerable Redis deployments, including through Redis replication abuse and CVE-2022-0543, then enrolls infected systems into a resilient P2P mesh that distributes updates and additional payloads without depending on centralized command-and-control infrastructure. Variants also scan for SSH services and conduct SSH password-brute-force activity to propagate.
P2PInfect targets Linux and Windows systems and has been observed in x86-64, ARM, and MIPS builds. It has affected internet-exposed Redis servers and cloud environments including Kubernetes clusters. The malware supports network scanning, P2P propagation, encrypted peer communications, payload delivery, anti-debugging and anti-forensic measures, self-updating behavior, and cryptocurrency mining. Some operations have maintained dormant infections for extended periods; P2PInfect infrastructure has also been associated with delivery of cryptominers and ransomware. Observed defense evasion includes packed binaries, wrapper executables, disabling core dumps, runtime modification of auxiliary components, firewall manipulation on Windows, and deletion of initial droppers. No definitive public attribution to a specific threat actor is established.
Capabilities
- Brute Force
- Crypto Theft
- Defense Evasion
- Initial Access
- Persistence
- Reconnaissance
- Scanning
Exploited software
Vulnerabilities linked to P2PInfect
3 CVEsMITRE ATT&CK