RedTail is a financially motivated Linux-focused threat actor associated with cryptojacking and botnet activity. Public reporting links the group to opportunistic exploitation of internet-exposed services and web applications, including vulnerabilities in Log4j, PAN-OS, ThinkPHP, and later high-value hosting infrastructure, to deploy mining malware and establish persistent access. The actor has been observed using private mining pools rather than public pools, a tradecraft choice that reduces visibility into wallet and pool infrastructure and suggests a more mature monetization model than commodity miners. RedTail has been associated with a malware framework also referred to as Multiverze, a substantially more capable evolution beyond a simple XMRig deployment. This tooling has been described as a multifunction Linux botnet written in Go that supports CPU and GPU mining, dynamic runtime configuration from command-and-control infrastructure, SSH-based worming and lateral movement, and multiple persistence mechanisms. Reported persistence methods include systemd service installation, SSH authorized_keys abuse, and a PAM authentication backdoor capable of surviving password changes. The malware has also been observed killing competing miners before installation and adapting to multiple Linux architectures, including x86_64, i686, aarch64, and arm variants. Operationally, RedTail combines exploitation with post-compromise automation. Observed techniques include exploitation of public-facing applications, SSH brute force, SFTP-based propagation, masquerading as legitimate system processes, and encrypted command-and-control over modern transport protocols. The actor’s malware reportedly parses known_hosts data to identify additional SSH targets and uses embedded credential dictionaries to expand laterally. Communications have been described as encrypted with ChaCha20-Poly1305 over HTTP/2 over TLS, limiting the value of static network indicators. Targeting appears broad and opportunistic, with emphasis on Linux servers and shared hosting environments where a single compromise can yield substantial compute resources and access to many downstream customer environments. In the context of shared hosting and control-panel compromises, likely post-exploitation outcomes include cryptomining, persistence establishment, tenant-wide access abuse, and potentially ransomware or other monetization activity. RedTail is best characterized as a cybercriminal actor rather than a confirmed nation-state group. Some reporting has speculated about possible geographic ties to Eastern Europe or Russia based on infrastructure patterns, but such attribution remains unconfirmed. Any suggested overlap with Lazarus has been assessed as low confidence and is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example cryptojacking group known for using private mining pools in XMRig-based mining operations.
A financially motivated cryptojacking botnet/framework targeting Linux systems. It uses exploit-based access and SSH brute-force propagation, deploys XMRig and NBminer for CPU/GPU mining, installs systemd persistence, writes SSH authorized_keys, and includes a PAM authentication backdoor that survives password changes. C2 communications are encrypted and mining configuration is delivered dynamically at runtime.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.