logo

'Hadooken' Linux malware targets Oracle WebLogic servers

ID: 7599109c-5562-5f58-97e5-1291e5d512da

STIX ID: report--7599109c-5562-5f58-97e5-1291e5d512da

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-09-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Aqua researchers observed attackers exploiting weak passwords on Oracle WebLogic servers to deploy a new Linux malware named “Hadooken.” The malware contains a cryptominer and the Tsunami DDoS/backdoor, creates cronjobs for persistence, can steal credentials for lateral movement, and was traced to two IP addresses; analysts also noted possible ties to RHOMBUS and NoEscape ransomware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.