Researchers reported that the P2PInfect worm, a Rust-based cross-platform malware family, expanded beyond earlier x86-64 infections to target ARM and MIPS systems, increasing the threat to IoT and embedded Linux environments. The worm spreads through multiple paths, including exploitation of Redis weaknesses and SSH brute-force activity, and uses a peer-to-peer architecture rather than a centralized command-and-control server, making disruption more difficult.
Analysis of newer samples showed the malware also incorporates self-protection and evasion features, including anti-debugging checks, disabled core dumps, runtime modification of a dropped auxiliary binary, and wrapper ELF files used to conceal the main payload. Telemetry tied the campaign to growing infection activity from late 2023 into early 2024, with observed malicious connections frequently originating from China, Hong Kong, and Singapore, while published research also included detection content such as YARA rules, infrastructure indicators, and malware hashes to support defender response.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
The report says observed P2PInfect SSH-propagation activity continued to grow through January 2024. Honeypot telemetry showed sustained infection attempts, with many malicious connections originating from China, Hong Kong, and Singapore.
On November 6, 2023, Nozomi Networks Labs honeypots intercepted a P2PInfect variant that propagated via SSH. This provided direct evidence of the worm using SSH abuse in addition to Redis exploitation.
Nozomi Networks Labs honeypots began recording initial P2PInfect infection commands in October 2023, marking observed activity tied to the worm's SSH-related propagation behavior.
The report states that the first known P2PInfect strains date back to at least July 2023. These early strains established the malware family before later expansion to additional architectures and propagation methods.
Embedded Windows DLL metadata found in P2PInfect samples indicated a compilation timestamp in May 2023, suggesting development activity may have begun before the malware's wider observed distribution.
Nozomi Networks Labs identified new P2PInfect samples targeting ARM architecture, expanding the malware's known reach beyond previously observed x86-64 and MIPS variants. The report states ARM targeting had not been reported by other researchers at the time.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 197 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.