Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise

Reported 20 May 2026 by otx · Severity: medium

An investigation identified persistent P2Pinfect botnet presence within Google Kubernetes Engine clusters at multiple organizations, with one compromise lasting six months. The intrusions originated from exposed Redis instances that provided initial access. The botnet utilizes a