'Hadooken' Linux malware targets Oracle WebLogic servers
ID: 7599109c-5562-5f58-97e5-1291e5d512da
STIX ID: report--7599109c-5562-5f58-97e5-1291e5d512da
Feed Name: The Register (Security)
Threat Score
Aqua researchers observed attackers exploiting weak passwords on Oracle WebLogic servers to deploy a new Linux malware named “Hadooken.” The malware contains a cryptominer and the Tsunami DDoS/backdoor, creates cronjobs for persistence, can steal credentials for lateral movement, and was traced to two IP addresses; analysts also noted possible ties to RHOMBUS and NoEscape ransomware families.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
