s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.p2pinfect

📛 Threat Title

Malware family: P2Pinfect

Category: P2Pinfect First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.p2pinfect`. Printable name: P2Pinfect.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    This complexity makes P2PInfect resilient to blocking and network firewall mitigation techniques. The worm's initial payload is written in Rust, and it uses TLS 1.3 to communicate with other P2P members on the current list of configured nodes. The C2 infrastructure updates automatically when the compromised node sends a request with all known ...

  • web:blog.netmanageit.com

    On July 11, 2023, Unit 42 cloud researchers discovered a new peer-to-peer (P2P) worm we call P2PInfect . Written in Rust, a highly scalable and cloud-friendly programming language, this worm is capable of cross-platform infections and targets Redis, a popular open-source database application that is heavily used within cloud environments.

  • web:cybersecuritynews.com

    P2Pinfect primarily spreads by exploiting the replication features in Redis, a popular in-memory data structure store. By abusing Redis's leader/follower topology, the malware gains code execution on follower nodes and propagates itself across the network. Additionally, P2Pinfect utilizes a limited SSH spreader to compromise higher-privilege ...

  • web:feedly.com

    Summary of the Original Report The P2PInfect botnet has been observed maintaining a persistent presence inside Google Kubernetes Engine clusters, with some infected environments remaining compromised for up to six months without remediation or detection.

  • web:live.paloaltonetworks.com

    Network Communication Behavior P2PInfect uses its P2P network to distribute follow-up malware to newly infected systems or cloud instances. When a system is first compromised, it will make a network connection to the P2P network and download the samples for the custom protocol to be used.

  • web:malpedia.caad.fkie.fraunhofer.de

    P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices.

  • web:thehackernews.com

    The peer-to-peer (P2) worm known as P2PInfect has witnessed a surge in activity since late August 2023, witnessing a 600x jump between September 12 and 19, 2023. "This increase in P2PInfect traffic has coincided with a growing number of variants seen in the wild, suggesting that the malware's developers are operating at an extremely high development cadence," Cado Security researcher Matt Muir ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infosecurity-magazine.com

    The cross-platform botnet known as P2Pinfect has been observed taking a significant leap in sophistication. Since its emergence in July 2023, this Rust-based malware has been on the radar for its rapid expansion, according to a new advisory published today by Cado Security. Initially exploiting ...

  • web:www.nozominetworks.com

    A highly sophisticated strain of malware known as P2PInfect is raising new concerns in the cybersecurity community. Developed in Rust, a language known for its safety and efficiency, this cross-platform worm uses several different methods of propagation to infect devices powered by different architectures.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.