P2PInfect is a Rust-based, cross-platform peer-to-peer worm and botnet active since 2023. It primarily targets internet-exposed Redis deployments, including vulnerable Debian-derived Redis installations affected by CVE-2022-0543 and misconfigured instances that permit abuse of replication functionality. The worm enrolls compromised systems into a decentralized mesh that distributes payloads, peer lists, and updates without dependence on a centralized command-and-control server. Observed variants also scan for SSH services and use password-spraying or brute-force attempts to propagate.
P2PInfect supports Linux and Windows payloads and has been observed in x86-64, ARM, and MIPS builds. It has targeted cloud and Kubernetes environments through exposed Redis services. The malware uses anti-analysis and defense-evasion measures including packed binaries, anti-debugging behavior, core-dump disabling, runtime modification of auxiliary components, wrapper executables, variable peer-communication ports, and self-updating payloads. Windows variants have used obfuscated PowerShell, firewall modifications, monitoring processes, and deletion of initial droppers to maintain botnet access.
The botnet can remain dormant for prolonged periods after infection. P2PInfect has been associated with the distribution of cryptomining and ransomware payloads, and its decentralized architecture complicates sinkholing and infrastructure takedown. Later activity linked P2PInfect peer infrastructure to exploitation of CVE-2025-11953 affecting React Native Metro servers, indicating expansion beyond Redis-focused propagation. No definitive public attribution to a specific threat actor is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The P2PInfect worm infects vulnerable Redis instances by exploiting the Lua sandbox escape vulnerability, CVE-2022-0543. P2PInfect exploits CVE-2022-0543 for initial access and then drops an initial payload that establishes P2P communication to a larger P2P network. | On July 11, 2023, Unit 42 cloud researchers discovered a new peer-to-peer (P2P) worm we call P2PInfect. Written in Rust, this worm is capable of cross-platform infections and targets Redis.
We also observed that some infected Redis nodes contacted P2Pinfect peers that were deployed by exploiting CVE-2025-11953 (aka Metro4Shell, a React vulnerability) in November 2025. | FortiGuard Labs recently identified persistent P2Pinfect presences within Google Kubernetes Engine (GKE) clusters at several client companies... While our telemetry indicated that no second-stage payload was ever executed, this botnet has been observed in the wild to remain dormant for extended periods before delivering ransomware and crypto miners.
FortiGuard Labs recently identified persistent P2Pinfect presences within Google Kubernetes Engine (GKE) clusters at several client companies... While our telemetry indicated that no second-stage payload was ever executed, this botnet has been observed in the wild to remain dormant for extended periods before delivering ransomware and crypto miners. | We also speculate with low confidence that P2Pinfect botnet might have incorporated CVE-2025-49844 (aka RediShell) in their repertoire.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
To infect new targets, P2PInfect executes a bruteforce attack against the device with the SSH server and, after a successful login, different commands are executed to download and run the malware.
Some variants of the P2Pinfect clients also have usermode rootkit capabilities.
The PowerShell script leveraged the encode command to obfuscate the communication initiation.
Interestingly, the latest variants of this malware tend to utilize a particular version of the UPX packer: 4.0.2.
Finally, lots of main ELF payloads are distributed inside wrapper ELF files that just print a famous “Hello, World!” message pretending this is its only functionality.
Once the core P2PInfect sample finishes execution, the payload will start scanning for additional hosts to compromise. The scanning operation focuses on exposed Redis hosts. However, researchers also found that compromised Redis instances also perform scanning attempts over port 22, SSH.
The malware is capable of performing Peer-to-Peer (P2P) communications without relying on a single Command and Control server (C&C) to propagate attackers’ commands.
The malware is capable of performing Peer-to-Peer (P2P) communications without relying on a single Command and Control server (C&C) to propagate attackers’ commands.
P2Pinfect is a self-propagating malware strain that combines worm-like spreading capabilities with a decentralized botnet architecture. This peer-to-peer (P2P) architecture makes it highly resilient to sinkholing and infrastructure takedowns.
P2PInfect uses its P2P network to distribute follow-up malware to newly infected systems or cloud instances.
218 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison to prior attacks abusing exposed Redis replication.
Mentioned only as a comparison to prior attacks abusing exposed Redis instances and replication functionality.
A worm malware referenced as targeting Linux and Windows Redis servers.
A resilient Rust-based peer-to-peer botnet/worm that compromises exposed Redis instances and other targets, maintains persistence through a decentralized mesh architecture, and is reportedly rented out to other criminals for deploying follow-on payloads such as ransomware or crypto miners.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.