TF-MAL-elf.p2pinfect
📛 Threat Title
Malware family: P2Pinfect
Description
ThreatFox malware family `elf.p2pinfect`. Printable name: P2Pinfect.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
This complexity makes P2PInfect resilient to blocking and network firewall mitigation techniques. The worm's initial payload is written in Rust, and it uses TLS 1.3 to communicate with other P2P members on the current list of configured nodes. The C2 infrastructure updates automatically when the compromised node sends a request with all known ...
-
web:blog.netmanageit.com
On July 11, 2023, Unit 42 cloud researchers discovered a new peer-to-peer (P2P) worm we call P2PInfect . Written in Rust, a highly scalable and cloud-friendly programming language, this worm is capable of cross-platform infections and targets Redis, a popular open-source database application that is heavily used within cloud environments.
-
web:cybersecuritynews.com
P2Pinfect primarily spreads by exploiting the replication features in Redis, a popular in-memory data structure store. By abusing Redis's leader/follower topology, the malware gains code execution on follower nodes and propagates itself across the network. Additionally, P2Pinfect utilizes a limited SSH spreader to compromise higher-privilege ...
-
web:feedly.com
Summary of the Original Report The P2PInfect botnet has been observed maintaining a persistent presence inside Google Kubernetes Engine clusters, with some infected environments remaining compromised for up to six months without remediation or detection.
-
web:live.paloaltonetworks.com
Network Communication Behavior P2PInfect uses its P2P network to distribute follow-up malware to newly infected systems or cloud instances. When a system is first compromised, it will make a network connection to the P2P network and download the samples for the custom protocol to be used.
-
web:malpedia.caad.fkie.fraunhofer.de
P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices.
-
web:thehackernews.com
The peer-to-peer (P2) worm known as P2PInfect has witnessed a surge in activity since late August 2023, witnessing a 600x jump between September 12 and 19, 2023. "This increase in P2PInfect traffic has coincided with a growing number of variants seen in the wild, suggesting that the malware's developers are operating at an extremely high development cadence," Cado Security researcher Matt Muir ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.infosecurity-magazine.com
The cross-platform botnet known as P2Pinfect has been observed taking a significant leap in sophistication. Since its emergence in July 2023, this Rust-based malware has been on the radar for its rapid expansion, according to a new advisory published today by Cado Security. Initially exploiting ...
-
web:www.nozominetworks.com
A highly sophisticated strain of malware known as P2PInfect is raising new concerns in the cybersecurity community. Developed in Rust, a language known for its safety and efficiency, this cross-platform worm uses several different methods of propagation to infect devices powered by different architectures.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.