Hadooken Malware Targeting Weblogic Servers (Campaign)
ID: 7212580b-6f54-54ff-b0e4-1a3a1d900d51
STIX ID: report--7212580b-6f54-54ff-b0e4-1a3a1d900d51
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-09-12
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers identified 'Hadooken', a Linux malware campaign targeting misconfigured Oracle WebLogic servers that leverages weak passwords to gain access, drops Tsunami malware and a cryptominer, uses shell/Python scripts for propagation and lateral movement via SSH, creates randomized cron jobs for persistence, clears logs to evade detection, and may enable future ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
