HeadCrab is a Redis-focused threat actor associated with a custom malware family of the same name used to compromise exposed Redis servers at scale. Activity has been observed since at least 2021, with infections numbering in the low thousands. The actor primarily targets internet-exposed Redis instances, particularly those with weak or absent authentication, and abuses Redis replication features to deliver a malicious Redis module. HeadCrab has been linked to large-scale resource hijacking for cryptocurrency mining. The actor is notable for developing a purpose-built Redis module that operates largely in memory and emphasizes stealth. Early variants used Redis replication and module-loading mechanisms to place malware on disk, while later variants evolved toward more fileless execution by using a loader and in-memory storage to reduce forensic artifacts. HeadCrab has also tampered with Redis logs, suppressed or altered command behavior, and manipulated Redis internals to hinder discovery and incident response. HeadCrab malware has implemented custom command-and-control functionality inside Redis, including command execution, encrypted communications, tunneling, file operations, and persistence-related actions. Earlier versions exposed custom Redis commands for operator control; later versions replaced those conspicuous commands with abuse of legitimate Redis functionality, including the MGET command, to blend malicious traffic with normal administration and application activity. The actor has also overridden or hooked native Redis commands such as configuration and replication-related commands as a defense-evasion measure. A later evolution commonly referred to as HeadCrab 2.0 demonstrated increased sophistication, including lower-level manipulation of Redis command-processing structures, fileless payload handling, and stealthier command-and-control patterns. The malware also showed signs of active adaptation in response to public detection research, indicating an operator capable of iterative development and operational refinement. HeadCrab is best characterized as a financially motivated intrusion set focused on opportunistic compromise of Redis infrastructure for cryptomining, with strong capabilities in initial access, persistence, defense evasion, post-exploitation, and covert remote control of infected servers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a campaign compromising Redis servers with custom malware, evolving from HeadCrab 1.0 to HeadCrab 2.0 with improved stealth, fileless loading, hooked Redis command handling, and enhanced defense evasion.
Operates a botnet targeting exposed/misconfigured Redis servers globally by abusing Redis replication (SLAVEOF) to load a malicious Redis module in-memory, establish encrypted C2, and primarily hijack resources for Monero cryptomining while maintaining high stealth (memory-only payloads via memfd, log deletion, command overriding, use of legitimate/hijacked IPs).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.