Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

HeadCrab malware targets Redis to mine cryptocurrency

Altszn.com by Altszn.com
February 2, 2023
in Monero
0
HeadCrab malware targets Redis to mine cryptocurrency
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


A malware known has “HeadCrab” is being used to mine cryptocurrency via Redis servers, and approximately 1,200 servers have been taken over, according to research published Wednesday by cloud security vendor Aqua Security.

Redis is a popular open source database management system (DBMS) first released in 2009. Aqua’s research blog post, co-written by security researcher Asaf Eitani and security data analyst Nitzan Yaakov, noted that because Redis is meant to operate on a secure and closed network, the DBMS does not come with authentication enabled by default. As such, Eitani and Yaakov wrote, Redis instances have increasingly been targeted by threat actors in recent years.

Aqua Security’s blog post focuses on HeadCrab, a botnet malware first discovered in September 2021 that has, to date, compromised at least 1,200 servers. The post contains significant technical details for HeadCrab, which Eitani and Yaakov describe as “sophisticated, long-developed malware” that can evade traditional antivirus products.

“We have noticed that the attacker has gone to great lengths to ensure the stealth of their attack,” the authors wrote. “The malware has been designed to bypass volume-based scans as it runs solely in memory and is not stored on disk. Additionally, logs are deleted using the Redis module framework and API. The attacker communicates with legitimate IP addresses, primarily other infected servers, to evade detection and reduce the likelihood of being blacklisted by security solutions.”

The attacker uses the “REPLICAOF” command to make the victim’s server a replica of another server controlled by the threat actor. The threat actor uses the malware to then create new Redis commands, enabling further control, and load malicious Redis modules onto the server.

Aqua Security discovered the malware because one of their honeypots was attacked. The attacker left a text note addressed to Aqua Security within the malware in which the attacker addressed themselves as HeadCrab — hence the malware name. The attacker said they were providing “unconditional basic income to [people] with some disadvantages.”

Aqua lead threat analyst Assaf Morag told TechTarget Editorial that the threat actor had no means of connecting the honeypot server to Aqua Security’s threat research department Team Nautilus, and that the actor did not contact Aqua directly. Morag suspects that the actor knew of Aqua Security due to the nature of HeadCrab’s campaign.

“The attacker discussed the transition from a tool that can easily be detected by security solutions to a partially fileless and fully fileless malware,” he said. “I believe he thought we had the highest chance to find such elusive malware because of our eBPF-based technology. And he was right.”

The HeadCrab botnet is primarily used for malicious cryptocurrency mining.

“The miner configuration file was extracted from memory and showed that the mining pools were mostly hosted on private legitimate IP addresses,” the post read. “Inspection of these IP addresses revealed that they belong to either clean hosts or a leading security company, making detection and attribution more difficult. One public Monero pool service was found in the configuration file but wasn’t used by the miner in runtime. The attacker’s Monero wallet showed an annual expected profit of almost $4,500 USD per worker, much higher than the typical $200 USD per worker.”

The blog post contained a map of compromised Redis instances, the majority of which appear to be in the Asia Pacific region, the U.S. and Western Europe.

Aqua Security made multiple recommendations in its post, such as ensuring Redis instances have configurations aligned with security best practices and initiating incident response should there be evidence of server compromise.

Redis did not respond to TechTarget Editorial’s request for comment at press time.

Alexander Culafi is a writer, journalist and podcaster based in Boston.



Read More: news.google.com

Tags: cryptocurrencyHeadCrabMalwareMoneroRedistargets
ADVERTISEMENT

Recent

Singapore Kicking Out Unlicensed Firms is Part of Global Trend

Singapore Kicking Out Unlicensed Firms is Part of Global Trend

June 7, 2025
Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

June 6, 2025
How to Earn Passive Income with Peer-to-Peer Lending

How to Earn Passive Income with Peer-to-Peer Lending

June 6, 2025

Categories

  • Bitcoin (4,411)
  • Blockchain (10,535)
  • Crypto (8,473)
  • Dark Web (408)
  • DeFi (7,980)
  • Ethereum (4,426)
  • Metaverse (6,555)
  • Monero (232)
  • NFT (963)
  • Solana (4,867)
  • Web3 (19,500)
  • Zcash (452)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Singapore Kicking Out Unlicensed Firms is Part of Global Trend

    Singapore Kicking Out Unlicensed Firms is Part of Global Trend

    June 7, 2025
    Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

    Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

    June 6, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 104,857.00
    • ethereumEthereum (ETH) $ 2,487.32
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.18
    • bnbBNB (BNB) $ 647.65
    • solanaSolana (SOL) $ 151.83
    • usd-coinUSDC (USDC) $ 0.999722
    • dogecoinDogecoin (DOGE) $ 0.185044
    • tronTRON (TRX) $ 0.279558
    • cardanoCardano (ADA) $ 0.664739
    • staked-etherLido Staked Ether (STETH) $ 2,486.33
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,839.00
    • hyperliquidHyperliquid (HYPE) $ 33.65
    • suiSui (SUI) $ 3.27
    • wrapped-stethWrapped stETH (WSTETH) $ 2,998.57
    • chainlinkChainlink (LINK) $ 13.94
    • avalanche-2Avalanche (AVAX) $ 20.69
    • leo-tokenLEO Token (LEO) $ 9.09
    • stellarStellar (XLM) $ 0.264820
    • bitcoin-cashBitcoin Cash (BCH) $ 407.10
    • the-open-networkToncoin (TON) $ 3.19
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • usdsUSDS (USDS) $ 0.999699
    • hedera-hashgraphHedera (HBAR) $ 0.168001
    • litecoinLitecoin (LTC) $ 87.95
    • wethWETH (WETH) $ 2,487.83
    • wrapped-eethWrapped eETH (WEETH) $ 2,661.32
    • polkadotPolkadot (DOT) $ 3.99
    • moneroMonero (XMR) $ 329.18
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999852
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.66
    • pepePepe (PEPE) $ 0.000011
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,889.00
    • pi-networkPi Network (PI) $ 0.624306
    • whitebitWhiteBIT Coin (WBT) $ 31.50
    • aaveAave (AAVE) $ 252.76
    • uniswapUniswap (UNI) $ 6.12
    • daiDai (DAI) $ 0.999433
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 374.86
    • okbOKB (OKB) $ 52.16
    • aptosAptos (APT) $ 4.73
    • nearNEAR Protocol (NEAR) $ 2.40
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097120
    • jito-staked-solJito Staked SOL (JITOSOL) $ 183.08
    • internet-computerInternet Computer (ICP) $ 5.03
    • ondo-financeOndo (ONDO) $ 0.830399
    • ethereum-classicEthereum Classic (ETC) $ 17.14
    • bitcoinBitcoin (BTC) $ 104,857.00
    • ethereumEthereum (ETH) $ 2,487.32
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.18
    • bnbBNB (BNB) $ 647.65
    • solanaSolana (SOL) $ 151.83
    • usd-coinUSDC (USDC) $ 0.999722
    • dogecoinDogecoin (DOGE) $ 0.185044
    • tronTRON (TRX) $ 0.279558
    • cardanoCardano (ADA) $ 0.664739
    • staked-etherLido Staked Ether (STETH) $ 2,486.33
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,839.00
    • hyperliquidHyperliquid (HYPE) $ 33.65
    • suiSui (SUI) $ 3.27
    • wrapped-stethWrapped stETH (WSTETH) $ 2,998.57
    • chainlinkChainlink (LINK) $ 13.94
    • avalanche-2Avalanche (AVAX) $ 20.69
    • leo-tokenLEO Token (LEO) $ 9.09
    • stellarStellar (XLM) $ 0.264820
    • bitcoin-cashBitcoin Cash (BCH) $ 407.10
    • the-open-networkToncoin (TON) $ 3.19
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • usdsUSDS (USDS) $ 0.999699
    • hedera-hashgraphHedera (HBAR) $ 0.168001
    • litecoinLitecoin (LTC) $ 87.95
    • wethWETH (WETH) $ 2,487.83
    • wrapped-eethWrapped eETH (WEETH) $ 2,661.32
    • polkadotPolkadot (DOT) $ 3.99
    • moneroMonero (XMR) $ 329.18
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999852
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.66
    • pepePepe (PEPE) $ 0.000011
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,889.00
    • pi-networkPi Network (PI) $ 0.624306
    • whitebitWhiteBIT Coin (WBT) $ 31.50
    • aaveAave (AAVE) $ 252.76
    • uniswapUniswap (UNI) $ 6.12
    • daiDai (DAI) $ 0.999433
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 374.86
    • okbOKB (OKB) $ 52.16
    • aptosAptos (APT) $ 4.73
    • nearNEAR Protocol (NEAR) $ 2.40
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.097120
    • jito-staked-solJito Staked SOL (JITOSOL) $ 183.08
    • internet-computerInternet Computer (ICP) $ 5.03
    • ondo-financeOndo (ONDO) $ 0.830399
    • ethereum-classicEthereum Classic (ETC) $ 17.14