Novel malware detected: HeadCrab

B2B Cyber ​​Security ShortNews

Share post

A security vendor warns of a new, elusive, and serious threat. Aqua's research unit, Team Nautilus, discovered a new, cutting-edge and novel piece of malware from a new group dubbed 'HeadCrab'.

The malware penetrates into Redis database servers and from then on remains mostly completely undetected, as it apparently cannot be detected by agentless and conventional antivirus solutions. The HeadCrab malware has been able to compromise a large number of Redis servers worldwide since September 2021 and has taken control of at least 1.200 servers to date.

Redis In-Memory Databases - Common and Vulnerable

Redis is an open source store for in-memory data structures that can be used as a database, cache or message broker. According to DB Engines, Redis is the most widely used key-value store, particularly because Redis is faster than relational databases such as MySQL for this purpose. Redis servers are vulnerable because they were originally designed to run on a secure, closed network rather than being exposed to the internet. That's why they don't have authentication enabled by default. This makes Redis servers accessible from the internet vulnerable to unauthorized access and command execution.

Measures to protect against HeadCrab

Aqua Security has created a detailed blog post about HeadCrab which can be found here. It explains the details of the HeadCrab attack, including the techniques the malware uses to remain undetected. Companies that use Redis servers can find detailed measures in the article that they can take to protect their systems.

More at Aquasec.com

 


About Aqua Security

Aqua Security stops cloud-native attacks and is the only company to guarantee security with a $2015 million Cloud-Native Protection Warranty. As the pioneer and largest pure-play cloud native security company, Aqua Security helps its customers innovate and shape the future of their business. The Aqua Platform is the industry's most integrated Cloud Native Application Protection Platform (CNAPP) that prioritizes risk and automates prevention, detection and response across the lifecycle. Founded in 1000, Aqua is headquartered in Boston and Ramat Gan, Israel, with Fortune 40 clients in over XNUMX countries.

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more