Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...
AI Analysis
Technical Summary
This threat involves a cryptomining botnet that compromised 3,562 Redis servers by exploiting unauthenticated Redis instances using rogue replication to inject cron jobs that deploy XMRig miners. The affected Redis versions range from 2.8.17 to 7.2.0, spanning both outdated and current Linux distributions, indicating that the primary issue is misconfiguration rather than a software vulnerability. The attacker toolkit, exposed via an open directory, contained Python exploit source code, campaign logs, and Windows registry hives. Additional attack vectors targeting WordPress, MongoDB, and SSH were included but did not result in confirmed compromises. A related open directory from February 2026 revealed Meterpreter deployment capabilities, extending the operator's activity timeline. The operation mined Monero via pool.moneroocean.stream using a wallet linked to the operator's own systems. No known exploits in the wild or vendor patches are documented.
Potential Impact
The operation resulted in the compromise of 3,562 Redis servers, enabling unauthorized cryptomining activities that consume system resources and potentially degrade performance. The exploitation leveraged misconfigured Redis instances lacking authentication, allowing attackers to inject cron jobs and deploy miners. While other attack vectors were included in the toolkit, no confirmed additional compromises occurred. The presence of Meterpreter capabilities suggests potential for further post-exploitation activities, increasing risk if similar misconfigurations persist. There is no indication of direct data theft or destruction from the provided information.
Mitigation Recommendations
Since the root cause is misconfiguration (unauthenticated Redis instances), remediation involves securing Redis servers by enabling authentication and restricting network access to trusted hosts only. No official patches are indicated as the issue is not a software vulnerability but a configuration weakness. Operators should audit Redis configurations to ensure authentication is enforced and disable or secure replication features to prevent rogue replication attacks. Monitoring for unauthorized cron jobs and removing any deployed miners is recommended. The vendor does not provide a specific advisory or patch; thus, patch status is not yet confirmed — check vendor advisories for updates.
Indicators of Compromise
- hash: f90c8b1dcd374d4f552744ee1765583d
- hash: 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a
- ip: 213.6.207.123
- domain: ayakliborsa.net
- domain: socket.ayakliborsa.net
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
Description
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a cryptomining botnet that compromised 3,562 Redis servers by exploiting unauthenticated Redis instances using rogue replication to inject cron jobs that deploy XMRig miners. The affected Redis versions range from 2.8.17 to 7.2.0, spanning both outdated and current Linux distributions, indicating that the primary issue is misconfiguration rather than a software vulnerability. The attacker toolkit, exposed via an open directory, contained Python exploit source code, campaign logs, and Windows registry hives. Additional attack vectors targeting WordPress, MongoDB, and SSH were included but did not result in confirmed compromises. A related open directory from February 2026 revealed Meterpreter deployment capabilities, extending the operator's activity timeline. The operation mined Monero via pool.moneroocean.stream using a wallet linked to the operator's own systems. No known exploits in the wild or vendor patches are documented.
Potential Impact
The operation resulted in the compromise of 3,562 Redis servers, enabling unauthorized cryptomining activities that consume system resources and potentially degrade performance. The exploitation leveraged misconfigured Redis instances lacking authentication, allowing attackers to inject cron jobs and deploy miners. While other attack vectors were included in the toolkit, no confirmed additional compromises occurred. The presence of Meterpreter capabilities suggests potential for further post-exploitation activities, increasing risk if similar misconfigurations persist. There is no indication of direct data theft or destruction from the provided information.
Defensive Guidance
Since the root cause is misconfiguration (unauthenticated Redis instances), remediation involves securing Redis servers by enabling authentication and restricting network access to trusted hosts only. No official patches are indicated as the issue is not a software vulnerability but a configuration weakness. Operators should audit Redis configurations to ensure authentication is enforced and disable or secure replication features to prevent rogue replication attacks. Monitoring for unauthorized cron jobs and removing any deployed miners is recommended. The vendor does not provide a specific advisory or patch; thus, patch status is not yet confirmed — check vendor advisories for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://hunt.io/blog/redis-cryptomining-botnet-3562-servers"]
- Adversary
- null
- Pulse Id
- 6aa03edde73b7cd2b94b199e
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashf90c8b1dcd374d4f552744ee1765583d | — | |
hash420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip213.6.207.123 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainayakliborsa.net | — | |
domainsocket.ayakliborsa.net | — |
Threat ID: 6aa12548acd9273b491543ee
Added to database: 09/09/2026, 09:22:16 UTC
Last enriched: 09/09/2026, 09:38:20 UTC
Last updated: 09/10/2026, 00:08:56 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.