RedTail, also identified as libredtail and associated with a Multiverze variant, is a financially motivated Linux cryptojacking operation and self-propagating botnet active since at least 2023. It deploys XMRig for CPU-based Monero mining and, in some variants, NBminer for GPU mining. Rather than embedding a cryptocurrency wallet in endpoints, RedTail uses operator-controlled private mining proxies and dynamically delivered runtime configuration. RedTail targets multiple Linux architectures and gains access through exploitation of exposed application and infrastructure vulnerabilities, unauthenticated container-management interfaces, and SSH password guessing. Reported exploitation includes vulnerabilities in Log4j, PAN-OS, ThinkPHP, PHPUnit, Apache HTTP Server, and PHP CGI. Its worm capability enumerates SSH targets from compromised hosts, attempts credentials from an embedded dictionary, and transfers payloads over SSH. The malware establishes persistence through system services, scheduled tasks, SSH authorized-key changes, and, in an advanced variant, a PAM authentication backdoor that can provide access independently of normal account-password changes. It collects host telemetry, masquerades as legitimate processes, removes competing miners, and terminates processes that may impede analysis. RedTail communications use encrypted custom command-and-control protocols and dynamically supplied mining configuration, while reported variants have also used encrypted HTTP/2-based communications and DNS-over-TLS for infrastructure resolution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated Linux cryptomining and worm operation. It deploys XMRig, spreads through exposed services and vulnerabilities, brute-forces SSH, establishes persistence, removes competing miners and debugging processes, and uses an operator-controlled proxy pool that substitutes the actual Monero wallet server-side.
Mentioned as an example cryptojacking group known for using private mining pools in XMRig-based mining operations.
A financially motivated cryptojacking botnet/framework targeting Linux systems. It uses exploit-based access and SSH brute-force propagation, deploys XMRig and NBminer for CPU/GPU mining, installs systemd persistence, writes SSH authorized_keys, and includes a PAM authentication backdoor that survives password changes. C2 communications are encrypted and mining configuration is delivered dynamically at runtime.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.