logo

REF6138 campaign (Campaign)

ID: a47d652e-d92c-5aee-a4f1-d6bfa97188a7

STIX ID: report--a47d652e-d92c-5aee-a4f1-d6bfa97188a7

Feed Name: Wiz Cloud Threat Landscape

Threat Score
68/100

Date Published: 2024-09-27

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Elastic Security Labs uncovered a March 2024 Linux-focused campaign that exploited an Apache2 web server flaw to deploy multiple malware families (including KAIJI DDoS and RUDEDEVIL cryptominer) and custom backdoors. The threat actors used cron jobs, SELinux modifications, process masquerading, Telegram-based C2 and encrypted channels to maintain persistence and actively develop new variants, with objectives appearing to be cryptomining and monetization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.