Redigo is malware that targets exposed Redis servers and has been observed compromising Redis instances to conscript them into malicious infrastructure. Reported activity links Redigo to denial-of-service, flooding, and brute-force operations conducted from compromised Redis hosts. It has also been associated with attacks in which Redis protections were disabled and server resources were hijacked for Monero cryptocurrency mining. Redigo is part of the broader pattern of Redis-focused malware that abuses weakly secured or internet-exposed deployments for resource theft and botnet-style abuse. High-confidence public reporting in the supplied material identifies Redis servers as the affected platform, but does not provide enough detail to support a more specific classification, delivery mechanism, or fuller behavioral profile with confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The P2PInfect worm infects vulnerable Redis instances by exploiting the Lua sandbox escape vulnerability, CVE-2022-0543. P2PInfect exploits CVE-2022-0543 for initial access and then drops an initial payload that establishes P2P communication to a larger P2P network. | This vulnerability has been used in previous attacks such as Muhstik and Redigo, both of which resulted in the compromised Redis instances participating in denial-of-service (DoS), flooding and brute-forcing attacks against other systems.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware that compromises Redis servers, disables protection features, and hijacks them for Monero cryptocurrency mining.
Malware/botnet previously seen exploiting the same vulnerability to turn compromised Redis instances into nodes used for DoS, flooding, and brute-force attacks.
Redis-targeting backdoor malware referenced for comparison; discussed as using Redis master-slave technique and (in prior reporting) associated with a Redis LUA sandbox escape leading to RCE (CVE-2022-0543).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.