Honeypot capture

kworker

VT 37/74

Entry is Redis cron injection. From there it kills 80-plus rival miners and uninstalls Alibaba and Tencent cloud-security agents using the vendors’ own tools, then trojanises ps, top and pstree to hide its XMRig, backdoors SSH and worms onward. The stage-2 miner, javae, was never recovered: the C2 did not serve it at fetch time.

Family
kworker
First seen
June 2026
Vector
Exposed Redis (cron injection)
Format
36 KB POSIX shell script (636 lines)
VirusTotal
37 engines: trojan.shell, 8220/kworkerds lineage
Tags
cryptominer · shell · redis · rootkit · worm
Report
The cryptominer that brings its own uninstaller
Sample
By request. Email [email protected]

SHA-256

  • 7420e819e6cf6d7608e475468ae0160185fe7eed0b5b4129aad3e8dabc776e30

← All captures