'Hadooken' Malware Targets Oracle's WebLogic Servers
ID: 51e9c329-dcc3-54aa-a95a-de88c9552489
STIX ID: report--51e9c329-dcc3-54aa-a95a-de88c9552489
Feed Name: Dark Reading
Aqua Nautilus observed a threat actor brute-forcing weak Oracle WebLogic admin credentials to deploy a malware family named 'Hadooken' that installs a cryptominer and the Tsunami DDoS bot, using nearly identical Python and shell scripts to persist via cron jobs and harvest SSH data for lateral movement; static analysis also found code links to ransomware families and the campaign used IPs previously seen in other botnet activity, indicating a notable risk to exposed WebLogic deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
