logo

Mirai Botnet Exploiting Apache OFBiz Vulnerability (Campaign)

ID: 545d1ce5-66c5-5a2b-a30c-e5a641fa4be3

STIX ID: report--545d1ce5-66c5-5a2b-a30c-e5a641fa4be3

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-07-31

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed active exploitation of Apache OFBiz CVE-2024-32113 (path traversal -> RCE) via the publicly accessible /webtools/control/forgotPassword endpoint by appending ";/ProgramExport" and abusing the groovyProgram parameter; attackers used URL parameters and POST requests to execute commands that download Mirai-like malware (examples using curl/wget) hosted at 185.196.10.231, with scanning activity indicating widespread probing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.