BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

RedisRaider Malware Hijacks Misconfigured Servers for Crypto Mining

RedisRaider Malware Hijacks Servers for Cryptocurrency

  • Security researchers identified a new Malware, RedisRaider, targeting misconfigured Redis servers for cryptocurrency mining.
  • The malware spreads aggressively using weak Redis settings and installs the XMRig Monero miner on Linux systems.
  • RedisRaider uses advanced obfuscation and anti-forensics methods to stay hidden and make detection difficult.
  • The campaign also involves a web-based Monero miner, expanding its reach beyond just server attacks.
  • Experts recommend stronger authentication, restricted access to Redis ports, and enhanced system monitoring as key defenses.

A newly discovered malware campaign named RedisRaider is compromising poorly configured Redis servers to mine cryptocurrency, according to findings by Datadog Security Labs. The malware, written in the Go programming language, exploits weak security settings to install the XMRig Monero mining software on Linux systems.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Researchers at Datadog Security Labs report that RedisRaider spreads quickly by scanning the internet for vulnerable Redis servers on the default port 6379. After confirming a system runs on Linux, the malware deploys itself using Redis database commands and sets up an automated task (called a cron job) to maintain its presence.

The attackers behind RedisRaider use advanced techniques to avoid detection. Their malware is heavily obfuscated using Garble, a tool that hides key functions in the code and makes analysis difficult. Additionally, the campaign uses methods like setting a short time-to-live for keys in Redis, generating temporary files in cron directories to blend with legitimate processes, and deleting keys and log files after execution.

The research team also found that RedisRaider infrastructure supports a web-based Monero miner. This extension lets attackers earn cryptocurrency from both infected Linux servers and unsuspecting website visitors. “In addition to server-side cryptojacking, RedisRaider’s infrastructure also hosted a web-based Monero miner, enabling a multi-pronged revenue generation strategy,” according to the Datadog Security Labs report.

One server linked to the campaign, operating on IP address 58.229.206[.]107, was running multiple database and web services. It also hosted a suspicious JavaScript file, suggesting coordinated activity across different platforms.

- Advertisement -

Experts recommend several defenses against this threat, including running Redis in protected mode, enabling strong authentication, restricting access to server ports, and continuously monitoring for unexpected jobs or files. Enhanced monitoring tools that can detect new cron job creation and known malware activity are also advised.

The report from Datadog Security Labs concludes that RedisRaider marks a significant new development in Linux-based cryptojacking threats, combining rapid self-spreading, complex system interactions, and layered methods for avoiding detection. Organizations are urged to review the configuration of their Redis servers, limit network exposure, and patch any weaknesses promptly.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Manifesto Reverses Course, Splits Backers

The Ethereum Foundation has released a new manifesto reaffirming its commitment to cypherpunk principles.The...

65TB of blockchain data now on Walrus via Allium

Allium is partnering with on-chain data platform Walrus to provide over 65TB of indexed...

SBF’s Trump Pardon Bid Fails Despite MAGA Praise

Sam Bankman-Fried's campaign for a pardon from President Donald Trump faces bipartisan opposition in...

XRP Hits $1.50, Eyes $1.60 Break Amid Record Holders

XRP (XRP) traded at $1.50 on Tuesday, a 3% rise in the past 24...

Study: Corporate AI Security Lags Due to Skills Gap

Two-thirds of security leaders lack visibility into how AI is used within their organizations,...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading