Redis servers attacked by Redigo malware
By MYBRANDBOOK
A new Go-based malware threat called Redigo has been targeting Redis servers are affected by CVE-2022-0543 vulnerability. It has plant a stealthy backdoor and allow command execution. Attackers continued to leverage it on unpatched machines several months after the fix came out in February this year, as proof-of-concept exploit code became publicly available.
The CVE-2022-0543 flaw is a Lua sandbox escape flaw that impacts Debian and Debian-derived Linux distributions. The vulnerability, which was rated 10 out of 10 for severity, could be exploited by a remote attacker with the ability to execute arbitrary Lua scripts to possibly escape the Lua sandbox and execute arbitrary code on the underlying machine. Juniper Threat Labs researchers reported that the Muhstik botnet has been observed targeting Redis servers exploiting the CVE-2022-0543 vulnerability.
Attacks with Redigo commence with port 6379 scans to discover exposed Redis instances, which will then be followed by the execution of several commands involving verification of the instance's vulnerability, creation of an attacking server copy, connection configurations, replication stream initiation, and module downloading from the downloaded dynamic library, according to an Aquasec report.
Host hardware information is being collected by the backdoor using its command execution capabilities prior to Redigo download and execution. While Redigo's processes following initial environment foothold remain uncertain due to attack duration limits in Aquasec honeypots, Aquasec researchers suspect that vulnerable servers may be added by the malware as a bot for distributed denial-of-service attacks and cryptocurrency mining attacks.
AquaSec researchers believe that threat actors are using the Redigo malware to infect Redis and add them to a botnet used to launch denial-of-service (DDoS) attacks, run cryptocurrency miners, or steal data from the servers.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
HIMACHAL FUTURISTIC COMMUNICATIONS LTD.
DELL TECHNOLOGIES INDIA PVT. LTD.
VERSA NETWORKS INDIA PVT. LTD.
LUMINOUS POWER TECHNOLOGIES PVT. LTD.
Icons Of India : NANDAN NILEKANI
Nandan Nilekani is the Co-Founder and Chairman of Infosys Technologies...
Icons Of India : B.V.R. Subrahmanyam
A 1987 batch (Chhattisgarh cadre) Indian Administrative Service Office...
Icons Of India : AALOK KUMAR
Aalok Kumar is celebrated as a global leader and recipient of the Peop...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
ECIL - Electronics Corporation of India Limited
ECIL is distinguished by its diverse technological capabilities and it...
C-DAC - Centre for Development of Advanced Computing
C-DAC is uniquely positioned in the field of advanced computing...
Indian Tech Talent Excelling The Tech World - JAY CHAUDHRY, CEO – Zscaler
Jay Chaudhry, an Indian-American technology entrepreneur, is the CEO a...
Indian Tech Talent Excelling The Tech World - Satya Nadella, Chairman & CEO- Microsoft
Satya Nadella, the Chairman and CEO of Microsoft, recently emphasized ...
Indian Tech Talent Excelling The Tech World - Sanjay Mehrotra, CEO- Micron Technology
Sanjay Mehrotra, the President and CEO of Micron Technology, is at the...