Hadooken Malware: A New Threat to WebLogic Servers
ID: 66d7e00c-087e-51af-88eb-2d8bf9849613
STIX ID: report--66d7e00c-087e-51af-88eb-2d8bf9849613
Feed Name: securityonline.info
Aqua Nautilus researchers report a new Linux malware family called Hadooken that targets Oracle WebLogic servers by exploiting known vulnerabilities or brute-forcing admin credentials; it uses multi-stage Python and shell scripts to install a cryptominer and the Tsunami backdoor, harvest SSH credentials for lateral movement, and clears logs to evade detection. The report urges patching WebLogic, enforcing strong passwords/MFA, monitoring network activity, and maintaining backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
