Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files

0
Medium
Published: 09/08/2026 (09/08/2026, 16:59:09 UTC)
Source: AlienVault OTX General

Description

An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 09:38:20 UTC

Technical Analysis

This threat involves a cryptomining botnet that compromised 3,562 Redis servers by exploiting unauthenticated Redis instances using rogue replication to inject cron jobs that deploy XMRig miners. The affected Redis versions range from 2.8.17 to 7.2.0, spanning both outdated and current Linux distributions, indicating that the primary issue is misconfiguration rather than a software vulnerability. The attacker toolkit, exposed via an open directory, contained Python exploit source code, campaign logs, and Windows registry hives. Additional attack vectors targeting WordPress, MongoDB, and SSH were included but did not result in confirmed compromises. A related open directory from February 2026 revealed Meterpreter deployment capabilities, extending the operator's activity timeline. The operation mined Monero via pool.moneroocean.stream using a wallet linked to the operator's own systems. No known exploits in the wild or vendor patches are documented.

Potential Impact

The operation resulted in the compromise of 3,562 Redis servers, enabling unauthorized cryptomining activities that consume system resources and potentially degrade performance. The exploitation leveraged misconfigured Redis instances lacking authentication, allowing attackers to inject cron jobs and deploy miners. While other attack vectors were included in the toolkit, no confirmed additional compromises occurred. The presence of Meterpreter capabilities suggests potential for further post-exploitation activities, increasing risk if similar misconfigurations persist. There is no indication of direct data theft or destruction from the provided information.

Defensive Guidance

Since the root cause is misconfiguration (unauthenticated Redis instances), remediation involves securing Redis servers by enabling authentication and restricting network access to trusted hosts only. No official patches are indicated as the issue is not a software vulnerability but a configuration weakness. Operators should audit Redis configurations to ensure authentication is enforced and disable or secure replication features to prevent rogue replication attacks. Monitoring for unauthorized cron jobs and removing any deployed miners is recommended. The vendor does not provide a specific advisory or patch; thus, patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://hunt.io/blog/redis-cryptomining-botnet-3562-servers"]
Adversary
null
Pulse Id
6aa03edde73b7cd2b94b199e
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf90c8b1dcd374d4f552744ee1765583d
hash420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a

Ip

ValueDescriptionCopy
ip213.6.207.123

Domain

ValueDescriptionCopy
domainayakliborsa.net
domainsocket.ayakliborsa.net

Threat ID: 6aa12548acd9273b491543ee

Added to database: 09/09/2026, 09:22:16 UTC

Last enriched: 09/09/2026, 09:38:20 UTC

Last updated: 09/10/2026, 00:08:56 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses