π¨ Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Fileshttps://www.reddit.com/r/netsec/comments/1wavoo6/redis_cryptomining_botnet_compromised_3562
Researchers indexed an open directory on 188.245.99.156 (Hetzner) that held an operator's full Redis cryptomining toolkit, not just a payload. 147 files in total: Python exploit source, JSON campaign logs, a bundled portable Python 3.11 runtime, and two exported Windows registry hives. Because the raw campaign logs were sitting there, the numbers come from the operator's own per-host records, not the summaries their scripts print: 3,562 distinct Redis servers compromised out of 12,966 targeted, across two independently coded runs The only technique that scaled is rogue replication: PING to coβ¦