FritzFrog Botnet Exploits Log4Shell on Overlooked Internal Hosts
ID: 7c9713ba-5221-5442-98c6-2abdff251b02
STIX ID: report--7c9713ba-5221-5442-98c6-2abdff251b02
Feed Name: Dark Reading
Threat Score
Executive Summary: A new FritzFrog botnet variant is actively spreading by brute-forcing SSH credentials and exploiting Log4Shell to pivot inside internal networks; it also abuses CVE-2021-4034 for privilege escalation and employs RAM-only techniques (memfd_create, /dev/shm), Tor, and antivirus-killing for stealth—the campaign has been associated with over 20,000 attacks against roughly 1,500 victims and can be mitigated by patching and stronger credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
