A new trojan that targets Linux servers running Redis has been discovered.
(
This trojan installs a cryptocurrency miner.
The odd fact about this trojan is that it includes a wormable feature that allows it to spread on its own.
The trojan, will look for Redis servers that don't have an admin account password, access the database, and then download itself on the new target.
Like a parasite stealing cpu time.
(
The trojan mines for the Monero crypto-currency, which targets vulnerable FTP servers.
There are over 30,000 Redis servers available online without a password, of which 6,000 have already been compromised by various threat actors.