REF6138 campaign (Campaign)
ID: a47d652e-d92c-5aee-a4f1-d6bfa97188a7
STIX ID: report--a47d652e-d92c-5aee-a4f1-d6bfa97188a7
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-09-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Elastic Security Labs uncovered a March 2024 Linux-focused campaign that exploited an Apache2 web server flaw to deploy multiple malware families (including KAIJI DDoS and RUDEDEVIL cryptominer) and custom backdoors. The threat actors used cron jobs, SELinux modifications, process masquerading, Telegram-based C2 and encrypted channels to maintain persistence and actively develop new variants, with objectives appearing to be cryptomining and monetization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
