Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners

Published September 9, 2026

Attackers found thousands of Redis servers left open on the internet and turned their processing power into a Monero cryptocurrency miner. This does not rely on a software bug but instead exploits weak security settings that let anyone send commands without a password.

Report priority
Medium

How it works

  • Attackers scanned the internet for Redis servers that did not require a password to send commands.
  • When they found one, they used Redis's built-in master-replica feature to add a scheduled task.
  • That task downloaded and ran a Monero miner in the background.
  • The miner runs every few minutes, using the server's CPU to generate Monero for the attackers.
  • This can slow down normal Redis operations, spike electricity or cloud bills, and even disrupt stored data if the miner overloads the server.

What to do

Check if your Redis server is exposed to the internet by testing if it responds to commands without a password. Run redis-cli -h your-server-ip ping in a terminal. If it replies with 'PONG', your server is vulnerable. Also, check your Redis logs for unusual CPU spikes or scheduled tasks you did not set up. If you see high processor use or unexpected tasks, your server may already be mining crypto.

Immediately add a password to your Redis server to block unauthorized command access. Update your Redis configuration file to require authentication. For Redis 6.x and later, add requirepass your-strong-password to the config file. For older versions, use auth your-strong-password. Restart Redis after making changes. If you suspect your server is already compromised, disconnect it from the internet, investigate logs for unauthorized tasks, and restore from a clean backup if needed.

Technical details

Attackers first scanned for Redis servers with no password protection. Once they found a vulnerable server, they sent a command to add a scheduled task. That task downloaded a Monero miner and started it automatically. The miner ran silently in the background, using the server's CPU to mine Monero for the attackers.

A cryptomining campaign exploited unauthenticated Redis servers (versions 2.8.17 through 7.2.0) to deploy XMRig miners, hijacking 3,562 systems. Attackers scanned for exposed Redis instances, then abused master-replica replication to inject a cron job that periodically downloads and executes the miner over encrypted port 443. The scheduled task evades detection by disguising itself as temporary system files, while the replication method works across all affected versions due to misconfigured authentication rather than a software flaw.

Victims experienced degraded performance, elevated CPU usage, and potential data disruption from the hijacked processes. Researchers at Hunters.io uncovered the campaign through exposed logs detailing two large-scale runs (3,388 and 2,862 hosts) with overlapping victims.