logo

FritzFrog Botnet Exploits Log4Shell on Overlooked Internal Hosts

ID: 7c9713ba-5221-5442-98c6-2abdff251b02

STIX ID: report--7c9713ba-5221-5442-98c6-2abdff251b02

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Executive Summary: A new FritzFrog botnet variant is actively spreading by brute-forcing SSH credentials and exploiting Log4Shell to pivot inside internal networks; it also abuses CVE-2021-4034 for privilege escalation and employs RAM-only techniques (memfd_create, /dev/shm), Tor, and antivirus-killing for stealth—the campaign has been associated with over 20,000 attacks against roughly 1,500 victims and can be mitigated by patching and stronger credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.