logo

Log4J – A Look into Threat Actors Exploitation Attempts

ID: a23bb6d5-b7bf-57c4-9b93-05fca8bd3526

STIX ID: report--a23bb6d5-b7bf-57c4-9b93-05fca8bd3526

Feed Name: Cato Networks

Threat Score
90/100

Date Published: 2021-12-13

Date Updated: 2026-07-23

Author: Dolev Moshe Attiya

...
...

On December 9 a critical zero-day in Apache Log4j (Log4Shell, CVE-2021-44228; CVSS 10) was disclosed and rapidly weaponized: public PoCs enabled widespread scanning, exploit attempts across many HTTP headers, sinkholing of successful probes, syntactic bypasses, and real-world exploitation that dropped an XMRig cryptominer. The report provides example payloads, describes scanner and attacker behaviors, and documents Cato Networks' rapid mitigation and detection rollout.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.