logo

'Hadooken' Malware Targets Oracle's WebLogic Servers

ID: 51e9c329-dcc3-54aa-a95a-de88c9552489

STIX ID: report--51e9c329-dcc3-54aa-a95a-de88c9552489

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-09-12

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Aqua Nautilus observed a threat actor brute-forcing weak Oracle WebLogic admin credentials to deploy a malware family named 'Hadooken' that installs a cryptominer and the Tsunami DDoS bot, using nearly identical Python and shell scripts to persist via cron jobs and harvest SSH data for lateral movement; static analysis also found code links to ransomware families and the campaign used IPs previously seen in other botnet activity, indicating a notable risk to exposed WebLogic deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.