
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
RediscryptominingbotnetcybersecurityXMRigMoneromalwareexploitvulnerabilitycryptocurrency
Researchers discovered an open directory containing a Redis cryptomining operator's complete toolkit with 147 files, including Python exploit source code, JSON campaign logs, and Windows registry hives. The logs revealed that 3,562 Redis servers were compromised out of 12,966 targeted across two campaigns using a rogue replication technique that exploited missing authentication to deploy XMRig cryptocurrency miners. The attacks targeted Redis versions 2.8.17 to 7.2.0, with SSH key injection and MongoDB attempts yielding zero successes. The same Monero wallet was found in a separate February 2026 open directory in Moldova containing Meterpreter and XMRig deployers, indicating at least five months of prior activity.