logo

Hadooken Malware: A New Threat to WebLogic Servers

ID: 66d7e00c-087e-51af-88eb-2d8bf9849613

STIX ID: report--66d7e00c-087e-51af-88eb-2d8bf9849613

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-09-16

Date Updated: 2026-04-22

Author: do son

...
...

Aqua Nautilus researchers report a new Linux malware family called Hadooken that targets Oracle WebLogic servers by exploiting known vulnerabilities or brute-forcing admin credentials; it uses multi-stage Python and shell scripts to install a cryptominer and the Tsunami backdoor, harvest SSH credentials for lateral movement, and clears logs to evade detection. The report urges patching WebLogic, enforcing strong passwords/MFA, monitoring network activity, and maintaining backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.