P2Pinfect

Malware type
botnet, worm
Family
Malware family
Last IoC activity
2026-07-03 10:36:06
Profile updated
2026-07-07 14:28:25

Context

P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices. It is capable of brute forcing SSH logins and exploiting Redis servers in order to propagate itself both to random IPs on the internet and to hosts it can find references to in files present on the infected system.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.P2Pinfect (report)
  • cadosecurity.com — From Dormant To Dangerous P2Pinfect Evolves To Deploy New Ransomware And Cryptominer (report)
  • Palo Alto Unit 42 — Peer To Peer Worm P2Pinfect (report)
  • cadosecurity.com — P2Pinfect New Variant Targets Mips Devices (report)
  • nozominetworks.com — P2Pinfect Worm Evolves To Target A New Platform (report)
  • cadosecurity.com — Redis P2Pinfect (report)
  • cadosecurity.com — Cado Security Labs Researchers Witness A 600X Increase In P2Pinfect Traffic (report)

External references