Honeypot capture
kworker
VT 37/74
Entry is Redis cron injection. From there it kills 80-plus rival miners and uninstalls Alibaba and Tencent cloud-security agents using the vendors’ own tools, then trojanises ps, top and pstree to hide its XMRig, backdoors SSH and worms onward. The stage-2 miner, javae, was never recovered: the C2 did not serve it at fetch time.
- Family
- kworker
- First seen
- June 2026
- Vector
- Exposed Redis (cron injection)
- Format
- 36 KB POSIX shell script (636 lines)
- VirusTotal
- 37 engines: trojan.shell, 8220/kworkerds lineage
- Tags
- cryptominer · shell · redis · rootkit · worm
- Report
- The cryptominer that brings its own uninstaller
- Sample
- By request. Email [email protected]
SHA-256
-
7420e819e6cf6d7608e475468ae0160185fe7eed0b5b4129aad3e8dabc776e30