{"rewrite":{"id":"r_e210ac08cf627bfeab2e7c35","clusterId":"c_d9f2ee937eb85d4ad9d8ec9c","slug":"p2pinfect-botnet-compromises-kubernetes-clusters-for-months","model":"deepseek-v4-flash","headline":"P2PInfect Botnet Compromises Kubernetes Clusters for Months","summary":"FortiGuard Labs has confirmed persistent P2PInfect activity within Google Kubernetes Engine clusters of multiple companies, with one compromise lasting six months. The infections originated from exposed Redis instances. Fortinet also identified a new deployment script and evidence that the botnet has expanded its attack targets beyond Redis to include React vulnerabilities.","whyItMatters":"The discovery shows that a single misconfiguration in a cloud environment can lead to a long-term, hard-to-remove botnet infection that resists standard takedown techniques.","webCardHtml":"\u003cp\u003eFortiGuard Labs has confirmed that the P2PInfect botnet maintained a persistent presence inside Google Kubernetes Engine clusters of multiple customer companies. In one case the compromise lasted six months. The infections began from externally exposed Redis instances, which gave the botnet its initial foothold. Fortinet telemetry did not detect second-stage payloads, but the botnet is known to deploy ransomware or cryptominers after long periods of inactivity. A new deployment script was also found. Some infected Redis nodes communicated with peers that had exploited CVE-2025-11953, a React vulnerability, indicating the botnet has expanded its targeting beyond Redis. Fortinet also believes, with low confidence, that P2PInfect may have incorporated CVE-2025-49844 into its methods.\u003c/p\u003e","blueskyPost":"P2PInfect's six-month undetected Kubernetes cluster compromise suggests the botnet's stealth mechanisms outpace current cluster monitoring. Fortinet found it expanded from Redis to React vulnerabilities.","twitterPost":"P2PInfect went undetected in a Kubernetes cluster for six months. It now targets React vulnerabilities beyond Redis.","threadsPost":"P2PInfect compromised a Kubernetes cluster for six months before detection. Fortinet's report also shows the botnet expanded beyond Redis to target React vulnerabilities, widening its attack surface.","newsletterBlurb":"FortiGuard Labs confirmed persistent P2PInfect activity inside Google Kubernetes Engine clusters of multiple companies, with one compromise lasting six months. The infections originated from exposed Redis instances. Fortinet also identified a new deployment script and evidence that the botnet has expanded beyond Redis to target React vulnerabilities.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/410/4410814/?rss\",\"title\":\"Kubernetes Compromise by P2PInfect Discovered in Multiple Companies\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4267,"outputTokens":544,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1781657878,"createdAt":"2026-06-17T00:45:56.000Z","publishedAt":"2026-06-17T00:49:57.000Z","updatedAt":"2026-06-17T00:49:57.000Z"},"cluster":{"id":"c_d9f2ee937eb85d4ad9d8ec9c","canonicalTitle":"複数企業で発見されたP2PInfectによるKubernetes侵害","representativeArticleId":"a_9f11e5175b3f2089e46f04aa","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-17T00:00:00.000Z","lastSeenAt":"2026-06-17T00:00:00.000Z","updatedAt":"2026-06-17T00:49:57.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/410/4410814/?rss","title":"複数企業で発見されたP2PInfectによるKubernetes侵害"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["FortiGuard Labs confirmed P2PInfect botnet activity inside Google Kubernetes Engine clusters of multiple companies, with one compromise lasting six months.","The infections originated from externally exposed Redis instances, which gave the botnet its initial foothold.","Fortinet identified a new deployment script and evidence that the botnet expanded its targets beyond Redis to include CVE-2025-11953, a React vulnerability.","Fortinet believes with low confidence that P2PInfect may have incorporated CVE-2025-49844 into its methods."]}
